CVE-2025-14532

CRITICAL

DobryCMS < 5.0 - Unauthenticated File Upload Remote Code Execution

Title source: manual
STIX 2.1

Description

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0054
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
studiofabryka/dorbycms 1.0 - 5.0
Published Mar 02, 2026
Tracked Since Mar 02, 2026