High severity7.1NVD Advisory· Published Oct 8, 2020· Updated Jun 17, 2026
CVE-2020-25263
CVE-2020-25263
Description
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyrocms/pyrocmsPackagist | <= 3.7 | — |
Affected products
3- PyroCMS/PyroCMSdescription
Patches
Vulnerability mechanics
References
4- gist.github.com/farid007/df51b0666643ec01d5571cbcc1e966e7nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vg2g-698h-v9w3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-25263ghsaADVISORY
- pyrocms.comnvdProduct
News mentions
0No linked articles in our index yet.