CVE-2025-29306

Published Mar 27, 2025

Last updated 9 months ago

Overview

Description
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
Source
cve@mitre.org
NVD status
Analyzed
Products
foxcms

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending
  1. CVE-2025-29306 – #Unauthenticated #Remote_Code_Execution in #FoxCMS v1.2.5 via #Unserialize_Injection https://t.co/G7esNGo2ZN https://t.co/OE9tidOb36

    @omvapt

    5 Jul 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Deep Dive: CVE-2025-29306 (RCE in FoxCMS via unserialize injection) ⚠️ CVSS 9.8 | EPSS 71.52% No auth. No patch. Just an id parameter passed to unserialize()—and suddenly you’re running system() on the server. Craft a serialized payload, drop it in a URL or curl command,

    @offsectraining

    3 Jul 2025

    3272 Impressions

    1 Retweet

    15 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2025-43859 2 - CVE-2025-31324 3 - CVE-2024-27876 4 - CVE-2025-32432 5 - CVE-2025-29306 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-29306 - FoxCMS Remote Code Execution Exploit. Remote code execution vulnerability in FoxCMS. This tool allows testing single targets or scanning multiple hosts in bulk. https://t.co/vaBIYfDP1u https://t.co/JCJnZvD06L

    @cyber_advising

    26 Apr 2025

    2998 Impressions

    25 Retweets

    62 Likes

    26 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2025-29306 - critical 🚨 FoxCMS v.1.2.5 - Remote Code Execution > An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the... 👾 https://t.co/W0rbTekYil @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    23 Apr 2025

    19 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  6. POC - CVE-2025-29306 FOXCMS / Code Execution Vulnerability https://t.co/exeNBVFZ9K

    @MatthewThomz

    17 Apr 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.