Critical severity9.1NVD Advisory· Published Jan 15, 2025· Updated Jun 17, 2026
CVE-2025-0502
CVE-2025-0502
Description
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:craftercms:craftercms:*:*:*:*:*:*:*:*range: >=4.0.0,<4.0.8
- (no CPE)range: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6
- (no CPE)range: 4.0.0
Patches
Vulnerability mechanics
References
1- craftercms.com/docs/current/security/advisory.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.