← Vulnerability feed

Vulnerability record · CVE-2025-57516 · published 29 September 2025

CVE-2025-57516: Publiccms os command injection vulnerability

Publiccms · Publiccms

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.

8.2 CVSS 3.1 High EPSS 1.1% · top 34.5% CWE-78 · OS command injection
8.2CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/sanluan/PublicCMS/issues/97 ExploitIssue TrackingVendor Advisory

Track CVE-2025-57516 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-25361Publiccms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…EPSS 0.71%9.8CVE-2023-46990Publiccms deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…EPSS 1.5%9.8CVE-2023-34852Publiccms incorrect permission assignment vulnerabilityPublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.EPSS 1.0%9.8CVE-2020-20914Publiccms sql injection vulnerabilitySQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.EPSS 1.1%9.8CVE-2020-20915Publiccms sql injection vulnerabilitySQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont…EPSS 1.1%9.8CVE-2021-27693Publiccms server-side request forgery (ssrf) vulnerabilityServer-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.EPSS 1.1%9.8CVE-2022-23389Publiccms os command injection vulnerabilityPublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.EPSS 22%9.8CVE-2021-40881Publiccms vulnerabilityAn issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2025-57516), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.