PT-2025-21165 · Invision · Invision Community

·

CVE-2025-47916

·

Published

2025-04-23

·

Updated

2025-07-14

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Invision Community versions 5.0.0 through 5.0.7
Description: The issue lies within the themeeditor controller, where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method, which is evaluated by the template engine. As a result, unauthenticated attackers can exploit this to inject and execute arbitrary PHP code by providing crafted template strings to the /applications/core/modules/front/system/themeeditor.php file.
Recommendations: For Invision Community versions 5.0.0 through 5.0.7, update to a version later than 5.0.7 to resolve the issue. As a temporary workaround, consider disabling the customCss method in the themeeditor controller until a patch is available. Restrict access to the themeeditor controller to minimize the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00290
CVE-2025-47916

Affected Products

Invision Community