CVE-2025-25967
Last modified
CVE-2025-25967 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ddsn | Acora Cms | 10.1.1 |
References
- https://github.com/padayali-JD/CVE-2025-25967Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-25967?
How severe is CVE-2025-25967?
How do I fix CVE-2025-25967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-25953Serosoft Solutions Pvt Ltd Academia Student Information Syst…6.5
- CVE-2025-25957Cross Site Scripting vulnerabilities in Xunruicms v.4.6.3 an…6.1
- CVE-2025-25958Cross Site Scripting vulnerabilities in phpcmsv9 v.9.6.3 all…5.4
- CVE-2025-2596Session logout could be overwritten in Checkmk GmbH's Checkm…5.3
- CVE-2025-25960Cross Site Scripting vulnerability in phpcmsv9 v.9.6.3 allow…6.1
- CVE-2025-25962An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.…9.8
- CVE-2025-25968DDSN Interactive cm3 Acora CMS version 10.1.1 contains an im…6
- CVE-2025-2597Reflected Cross-Site Scripting (XSS) in ITIUM 6050 version 5…6.1
- CVE-2025-25973A stored Cross Site Scripting vulnerability in the "related …6.5
- CVE-2025-25975An issue in parse-git-config v.3.0.0 allows an attacker to o…7.5
- CVE-2025-25977An issue in canvg v.4.0.2 allows an attacker to execute arbi…9.8
- CVE-2025-2598When the AWS Cloud Development Kit (AWS CDK) Command Line In…5.7
Are you affected by CVE-2025-25967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
