CVE-2025-69437Disclosure(publiccms / publiccms)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • publiccms

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
publiccms

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-27: 3Mentions · 2026-03-04: 1Technical Details · 2026-02-27: 3Technical Details · 2026-03-04: 102-2703-04
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-273
Disclosure3
2026-03-041
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-69437 (CVSS:8.7, HIGH) is Awaiting Analysis. PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ..https://nvd.nist.gov/vuln/detail/CVE-2025-69437 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2025-69437, a stored XSS flaw in PublicCMS that allows JavaScript payloads in PDFs, but it does not provide a PoC, exploit code, or patch information.

    0000058
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69437 Stored XSS in PublicCMS v5.202506.d via Malicious PDF File Upload https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69437

    Post summary

    The post announces a new stored XSS vulnerability (CVE-2025-69437) in PublicCMS v5.202506.d that can be triggered by uploading malicious PDF files, with details listed on Vulmon.

    0000068
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-69437 - High PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend http://CmsFileUtils.java. If a user uploads... https://www.thehackerwire.com/vulnerability/CVE-2025-69437/ https://t.co/p29tUXSik6

    Post summary

    PublicCMS v5.202506.d is exposed to stored XSS via uploaded PDFs that bypass backend PDF security checks, presenting a high‑severity flaw.

    00000134
    119 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69437 PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtil… https://www.cve.org/CVERecord?id=CVE-2025-69437

    Post summary

    PublicCMS v5.202506.d and earlier are vulnerable to stored XSS, allowing attackers to embed JavaScript in PDFs that bypass backend PDF security checks.

    00000141
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppubliccmspubliccms---

Explore more