Critical severity9.8NVD Advisory· Published Feb 26, 2025· Updated Jul 5, 2026
CVE-2025-25790
CVE-2025-25790
Description
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/Ka7arotto/FoxCMS/blob/main/FoxCMS-upload-rce.mdnvdExploit
- www.foxcms.cnnvdProduct
News mentions
0No linked articles in our index yet.