CVE-2025-29306
CRITICAL EXPLOITED NUCLEIFoxCMS v.1.2.5 - Remote Code Execution
Title source: nucleiDescription
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
Exploits (9)
nomisec
WORKING POC
6 stars
by Mattb709 · remote
https://github.com/Mattb709/CVE-2025-29306-PoC-FoxCMS-RCE
nomisec
WORKING POC
1 stars
by inok009 · remote
https://github.com/inok009/FOXCMS-CVE-2025-29306-POC
Nuclei Templates (1)
FoxCMS v.1.2.5 - Remote Code Execution
CRITICALVERIFIEDby ritikchaddha
Shodan:
html:"foxcms-logo"
FOFA:
(body="foxcms-logo" || body="foxcms-container") && body="div"
Scores
CVSS v3
9.8
EPSS
0.8436
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-06-07
CWE
CWE-94
Status
published
Products (1)
foxcms/foxcms
< 1.2
Published
Mar 27, 2025
Tracked Since
Feb 18, 2026