CVE-2025-47637Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web Server.This issue affects STAGGS: from n/a through <= 2.11.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-26: 2PoC Mentioned / Linked · 2026-05-26: 2Patch / Workaround · 2026-05-26: 2Technical Details · 2026-05-26: 105-26
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    PoC

    CVE-2025-47637 Workaround available, CVE Alerts, YARA Rule, Sigma Rule, Suricate Rule, POC available at website compellable free of charge! #CVE #Cvealert #Cybersecurity #infosec #developers #hackers https://t.co/NqGXiBwAw6

    Post summary

    The tweet announces CVE‑2025‑47637, noting that a workaround is available and that a proof of concept can be accessed through a free website, accompanied by detection rules.

    10000262
    904 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2025-47637 - Critical arbitrary file upload in Staggs &lt;= 2.11.0. Allows web shell upload. CVSS 10.0. No patch available. Disable or isolate immediately. #CVE #infosec #cybersecurity #CVEAlert #POC More info Yara, Sigma rules and etc available: https://www.valtersit.com/cve/CVE-2025-47637/

    Post summary

    The post announces CVE-2025-47637, a critical arbitrary file upload flaw in Staggs version 2.11.0 or earlier, with CVSS 10.0, noting no patch exists and recommending disabling or isolating the affected system.

    00000194
    904 followersView on X

Explore more