← Vulnerability feed

Vulnerability record · CVE-2025-29306 · published 27 March 2025

CVE-2025-29306: FoxCMS index.html case display page code injection

Foxcms · Foxcms

FoxCMS 1.2.5 contains a code injection flaw (CWE-94) reachable through the case display page in the index.html component, allowing a remote attacker to execute arbitrary code. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a severe pre-auth remote code execution risk for exposed installations.

9.8 CVSS 3.1 Critical EPSS 47% · top 1.2% CWE-94 · Code injection
9.8CVSS 3.1 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required and a public exploit reference makes this a critical pre-auth RCE risk.

What it is

FoxCMS 1.2.5 contains a code injection flaw (CWE-94) reachable through the case display page in the index.html component, allowing a remote attacker to execute arbitrary code. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, this is a severe pre-auth remote code execution risk for exposed installations.

Impact

An unauthenticated remote attacker can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability of the FoxCMS host and any data it serves.

Attack surface

Reached over the network via the case display page in the index.html component; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.46583 (98.8th percentile) and a public exploit reference exists on GitHub, indicating meaningful and elevated exploitation likelihood.

What to do

  • Apply the vendor fix for FoxCMS 1.2.5 or upgrade to a patched release as soon as one is available; if no patch exists, restrict or disable the case display page.
  • Place FoxCMS behind a WAF or reverse proxy with rules blocking code-injection patterns targeting the index.html case display endpoint.
  • Remove or restrict public internet exposure of FoxCMS administrative and content pages until patched.
  • Run the web service with least privilege and isolate it from sensitive internal systems to limit post-exploitation reach.

Detection

  • Monitor web logs for suspicious requests to the index.html case display page containing code or template injection payloads.
  • Alert on unexpected child processes spawned by the web server (e.g., shell, curl, wget) indicating code execution.
  • Review file integrity on FoxCMS web directories for newly written or modified files after page requests.
  • Correlate outbound network connections from the FoxCMS host with inbound requests to the vulnerable page.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/somatrasss/CVE-2025-29306 ExploitThird Party Advisory

Track CVE-2025-29306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-50692Foxcms code injection vulnerabilityFoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.EPSS 0.65%9.8CVE-2025-25789Foxcms code injection vulnerabilityFoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.EPSS 1.3%9.8CVE-2025-25790Foxcms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via…EPSS 0.91%8.8CVE-2025-55422Foxcms cross-site scripting vulnerabilityIn FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.EPSS 0.42%8.8CVE-2025-55409Foxcms cross-site scripting vulnerabilityFoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.EPSS 0.49%8.8CVE-2025-55420Foxcms cross-site scripting vulnerabilityA Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is…EPSS 0.49%8.4CVE-2025-46154Foxcms sql injection vulnerabilityFoxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.EPSS 0.22%7.3CVE-2025-56630Foxcms sql injection vulnerabilityFoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2025-29306), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.