- Description
- PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- publiccms
CVSS 3.1
- Type
- Secondary
- Base score
- 8.7
- Impact score
- 5.8
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-79
- Hype score
- Not currently trending
CVE-2025-69437: PDF upload → stored XSS → admin session hijack. "Just an XSS" said someone, right before losing the admin account. Document uploads are attack vectors since 2010. Still handled like internal memos. CSP, admin isolation, or enjoy your pivot point.
@CisoRaging77913
5 Mar 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-69437 (CVSS:8.7, HIGH) is Awaiting Analysis. PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ..https://t.co/SzTf9Na2Gx #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
4 Mar 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-69437 Stored XSS in PublicCMS v5.202506.d via Malicious PDF File Upload https://t.co/hdc6U5IhPZ
@VulmonFeeds
27 Feb 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🟠 CVE-2025-69437 - High PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend https://t.co/4Tc3HFVO2z. If a user uploads... https://t.co/jkybelJ64B https://t.co/p29tUXSik6
@TheHackerWire
27 Feb 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-69437 PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtil… https://t.co/1ZFOFo1PlH
@CVEnew
27 Feb 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:publiccms:publiccms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B937509A-33F9-4B58-9E04-4297591A198E",
"versionEndIncluding": "5.202506.d",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]