CVE-2025-51818

MEDIUM

MCCMS 2.7.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 26.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-552
Status published
Products (1)
chshcms/mccms 2.7
Published Aug 21, 2025
Tracked Since Feb 18, 2026