PT-2025-48548 · Publiccms+1 · Publiccms+1

Published

2025-12-01

·

Updated

2025-12-04

·

CVE-2025-65840

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PublicCMS version 5.202506.b
Description PublicCMS version 5.202506.b is susceptible to a Cross Site Request Forgery (CSRF) issue within the CkEditorAdminController. This allows an attacker to potentially perform actions on behalf of an authenticated user without their knowledge. The vulnerable component is the CkEditorAdminController.
Recommendations Apply any available updates to address the issue in the CkEditorAdminController.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-65840

Affected Products

Ckeditor
Publiccms