VYPR

Siemprecms File Upload Abuse

by Drew Byte

Source repositories

CVEs (1)

  • CVE-2025-10116HigSep 9, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used.