PT-2025-39558 · Javothemes · Javo Core

Published

2025-09-26

·

Updated

2025-10-01

·

CVE-2025-60111

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Javothemes Javo Core versions through 3.0.0.266
Description A Cross-Site Request Forgery (CSRF) issue exists in Javothemes Javo Core, potentially allowing Authentication Bypass. This occurs due to insufficient validation of requests, which could allow an attacker to perform actions on behalf of an authenticated user without their knowledge.
Recommendations Update Javo Core to a version later than 3.0.0.266.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-60111

Affected Products

Javo Core