PT-2026-3993 · Blazethemes · News Event

Published

2026-01-22

·

Updated

2026-01-25

·

CVE-2025-62056

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions blazethemes News Event versions through 1.0.1
Description An issue exists in blazethemes News Event news-event that allows for unrestricted file uploads with dangerous file types. The vulnerability allows attackers to upload malicious files, potentially leading to system compromise.
Recommendations Update to a version later than 1.0.1.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-62056

Affected Products

News Event