CVE-2025-55040General(murasoftware / mura_cms)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker-controlled forms when an authenticated administrator visits a crafted webpage. Full exploitation of this vulnerability would require the victim to select a malicious ZIP file containing form definitions, which can be automatically generated by the exploit page and used to create data collection forms that steal sensitive information. Successful exploitation of the import form CSRF vulnerability could result in the installation of malicious data collection forms on the target MuraCMS website that can steal sensitive user information. When an authenticated administrator visits a malicious webpage containing the CSRF exploit and selects the attacker-generated ZIP file, their browser uploads and installs form definitions that create legitimate forms that could be designed with malicious content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mura_cms

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
mura_cms

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 103-1803-19
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1General1
2026-03-191
General1
Full discourse3 posts
  • NerdieNews@NewsNerdie
    General

    Top cybersecurity news: CVE-2026-32255: Kan project management tool versions 0.5.4 and below are vulnerable to unauthenticated SSRF via the attachment download endpoint, posing significant security risks. CVE-2026-32805: Romeo's archive sanitization process is susceptible to path traversal due to missing checks, potentially allowing unauthorized access. CVE-2025-55040: MuraCMS faces a CSRF vulnerability, enabling attackers to upload malicious form definitions without user consent. CVE-2026-32000: OpenClaw versions before 2026.2.19 are vulnerable to command injection via the Lobster tool, exposing systems to potential shell metacharacter attacks. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #ZeroDay #PatchTuesday

    Post summary

    The post lists several CVEs with brief technical details but does not provide any PoC, exploit code, active exploitation evidence, or patch information.

    0000036
    49 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-55040 - High The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function... https://www.thehackerwire.com/vulnerability/CVE-2025-55040/ https://t.co/bzcQUp7OuJ

    Post summary

    This post announces CVE-2025-55040 as a CSRF flaw in MuraCMS 10.1.10 that permits uploading malicious form definitions, but it offers no PoC, exploit code, patch details, or evidence of active exploitation.

    0000095
    138 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-55040 The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable … https://www.cve.org/CVERecord?id=CVE-2025-55040

    Post summary

    The post notes a CSRF flaw in MuraCMS up to version 10.1.10 that permits attackers to upload malicious form definitions, but provides no further details on PoC, exploitation, or fixes.

    00000195
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmurasoftwaremura_cms---

Explore more