← Vulnerability feed

Vulnerability record · CVE-2025-65840 · published 1 December 2025

CVE-2025-65840: Publiccms cross-site request forgery vulnerability

Publiccms · Publiccms

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

8.8 CVSS 3.1 High EPSS 0.18% · top 93.7% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-65840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-25361Publiccms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…EPSS 0.71%9.8CVE-2023-46990Publiccms deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…EPSS 1.5%9.8CVE-2023-34852Publiccms incorrect permission assignment vulnerabilityPublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.EPSS 1.0%9.8CVE-2020-20914Publiccms sql injection vulnerabilitySQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.EPSS 1.1%9.8CVE-2020-20915Publiccms sql injection vulnerabilitySQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont…EPSS 1.1%9.8CVE-2021-27693Publiccms server-side request forgery (ssrf) vulnerabilityServer-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.EPSS 1.1%9.8CVE-2022-23389Publiccms os command injection vulnerabilityPublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.EPSS 22%9.8CVE-2021-40881Publiccms vulnerabilityAn issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2025-65840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.