VYPR

CMS

by Badaso

CVEs (1)

  • CVE-2025-52353CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server…