CVE-2025-51818

MEDIUM

MCCMS 2.7.0 - Arbitrary File Deletion via Backups.php

Title source: llm
STIX 2.1

Description

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 14.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-552
Status published
Products (1)
chshcms/mccms 2.7
Published Aug 21, 2025
Tracked Since Feb 18, 2026