CVE-2025-14532

CRITICAL

DobryCMS <5.0 - RCE

Title source: llm
STIX 2.1

Description

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

Scores

CVSS v3 9.8
EPSS 0.0025
EPSS Percentile 48.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
studiofabryka/dorbycms 1.0 - 5.0
Published Mar 02, 2026
Tracked Since Mar 02, 2026