VYPR

Translate Module

by Bitrix

CVEs (2)

  • CVE-2025-67887CriMay 8, 2026
    risk 0.64cvss 9.8epss 0.02

    1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for…

  • CVE-2025-67886MedMay 8, 2026
    risk 0.41cvss 6.3epss 0.01

    Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for…