Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:LDefault status
unaffected
1.0 (semver)
affected
2.0 (semver)
affected
5.0 (semver)
affected
Description
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
1.0 (semver)
2.0 (semver)
5.0 (semver)
Credits
Dawid Radziński (RED SECURITY)
References
cert.pl/posts/2026/03/CVE-2025-12462/