CVE-2025-24708Patch

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-dynamics-crm allows Reflected XSS.This issue affects WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 103-31
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Patch

    Roundcube Webmail 1.6.14 がリリース:任意ファイル書き込みなど複数の深刻な欠陥を修正 https://iototsecnews.jp/2026/03/24/roundcube-webmail-security-updates-patches-multiple-critical-vulnerabilities/ 今回の脆弱性 CVE-2025-24708/CVE-2025-24709 などの主な原因は、セッション・ハンドラにおけるデータの不適切なデシリアライズ処理にあります。それにより、認証を受けていない第三者が悪意の命令を送り込み、サーバ上で任意のファイルを操作できる状態になっていました。また、パスワード変更時のロジック不備や、外部リソースの読み込み制限の不足といった、実装上の細かなミスが重なったことも、被害を広げる要因になり得ます。ご利用のチームは、ご注意ください。 #CVE202524708 #CVE202524709 #Roundcube #Vulnerability #Webmail

    Post summary

    Roundcube Webmail 1.6.14 has been released to fix CVE‑2025‑24708 and CVE‑2025‑24709, vulnerabilities that allow unauthenticated attackers to perform arbitrary file operations via improper deserialization.

    01000255
    481 followersView on X

Explore more