← Vulnerability feed

Vulnerability record · CVE-2025-8120 · published 30 September 2025

CVE-2025-8120: Widzialni pad cms unrestricted file upload vulnerability

Widzialni · Pad Cms

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

10.0 CVSS 4.0 Critical EPSS 0.59% · top 54.1% CWE-434 · Unrestricted file upload
10.0CVSS 4.0 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert.pl/posts/2025/09/CVE-2025-7063 Third Party Advisory

Track CVE-2025-8120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-7063Widzialni pad cms unrestricted file upload vulnerabilityDue to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of…EPSS 0.63%10.0CVE-2025-7065Widzialni pad cms unrestricted file upload vulnerabilityDue to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files o…EPSS 0.63%8.7CVE-2025-8122Widzialni pad cms sql injection vulnerabilityImproper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…EPSS 0.32%8.7CVE-2025-8121Widzialni pad cms sql injection vulnerabilityImproper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This iss…EPSS 0.30%8.7CVE-2025-8117Widzialni pad cms vulnerabilityPAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password fun…EPSS 0.27%6.9CVE-2025-8118Widzialni pad cms improper restriction of authentication attempts vulnerabilityPAD CMS implements weak client-side brute-force protection by utilizing two cookies:  login_count and login_timeout. Information about attempt count …EPSS 0.22%5.1CVE-2025-8119Widzialni pad cms cross-site request forgery vulnerabilityPAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visit…EPSS 0.13%5.1CVE-2025-8116Widzialni pad cms cross-site scripting vulnerabilityPAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbi…EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2025-8120), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.