Unrated severityNVD Advisory· Published Jul 31, 2025· Updated Jul 31, 2025
CVE-2025-54752
CVE-2025-54752
Description
Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file. If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.
Affected products
1- Alfasado Inc./PowerCMSv5Range: 4.6 and earlier (PowerCMS 4.x series)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.