← Vulnerability feed

Vulnerability record · CVE-2025-8116 · published 30 September 2025

CVE-2025-8116: Widzialni pad cms cross-site scripting vulnerability

Widzialni · Pad Cms

PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

5.1 CVSS 4.0 Medium EPSS 0.25% · top 85.6% CWE-79 · Cross-site scripting
5.1CVSS 4.0 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert.pl/posts/2025/09/CVE-2025-7063 Third Party Advisory

Track CVE-2025-8116 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-8120Widzialni pad cms unrestricted file upload vulnerabilityDue to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files o…EPSS 0.59%10.0CVE-2025-7063Widzialni pad cms unrestricted file upload vulnerabilityDue to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of…EPSS 0.63%10.0CVE-2025-7065Widzialni pad cms unrestricted file upload vulnerabilityDue to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files o…EPSS 0.63%8.7CVE-2025-8122Widzialni pad cms sql injection vulnerabilityImproper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…EPSS 0.32%8.7CVE-2025-8121Widzialni pad cms sql injection vulnerabilityImproper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…EPSS 0.30%8.7CVE-2025-8117Widzialni pad cms vulnerabilityPAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password fun…EPSS 0.27%6.9CVE-2025-8118Widzialni pad cms improper restriction of authentication attempts vulnerabilityPAD CMS implements weak client-side brute-force protection by utilizing two cookies:  login_count and login_timeout. Information about attempt count …EPSS 0.22%5.1CVE-2025-8119Widzialni pad cms cross-site request forgery vulnerabilityPAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visit…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2025-8116), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.