PT-2025-27115 · Unknown · Everest Forms

Published

2025-06-27

·

Updated

2025-09-13

·

CVE-2025-52709

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Everest Forms versions through 3.2.2
Description: Deserialization of untrusted data in Everest Forms allows for object injection. This issue impacts installations with PHP versions below 7.1, potentially leading to remote code execution (RCE) when an administrator views form submissions. It is estimated that over 100,000 sites are affected.
Recommendations: Update to version 3.2.3.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-52709

Affected Products

Everest Forms