CVE-2026-25870Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implementation does not enforce allowlists, block internal or private IP address ranges, or apply request timeouts or response size limits. An attacker can abuse this behavior to induce the server to issue outbound requests to arbitrary hosts, including internal network resources, potentially enabling internal network scanning and denial of service through resource exhaustion.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 102-1002-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25870 Server-Side Request Forgery (SSRF) in DoraCMS 3.1 UEditor Image Fetch Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25870

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability in DoraCMS 3.1’s UEditor image fetch feature, without indicating exploitation or remediation.

    0001079
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25870 DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts use… https://www.cve.org/CVERecord?id=CVE-2026-25870

    Post summary

    CVE-2026-25870 is a server‑side request forgery vulnerability in DoraCMS 3.1 and earlier, affecting the UEditor remote image fetch feature. No PoC, exploit, patch, or active exploitation information is provided.

    00010183
    56.5K followersView on X

Explore more