← Vulnerability feed

Vulnerability record · CVE-2025-8912 · published 13 August 2025

CVE-2025-8912: Wellchoose organization portal system path traversal vulnerability

Wellchoose · Organization Portal System

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

8.7 CVSS 4.0 High EPSS 0.58% · top 54.5% CWE-36 · CWE-36CWE-22 · Path traversal
8.7CVSS 4.0 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8912 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-3826Wellchoose organization portal system php remote file inclusion vulnerabilityIFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the se…EPSS 0.86%9.3CVE-2025-8913Wellchoose organization portal system php remote file inclusion vulnerabilityOrganization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arb…EPSS 0.63%7.1CVE-2025-8914Wellchoose organization portal system sql injection vulnerabilityOrganization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary S…EPSS 0.39%7.1CVE-2025-8909Wellchoose organization portal system path traversal vulnerabilityOrganization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to …EPSS 0.65%5.3CVE-2025-8911Wellchoose organization portal system cross-site scripting vulnerabilityOrganization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to e…EPSS 0.35%5.3CVE-2025-8910Wellchoose organization portal system cross-site scripting vulnerabilityOrganization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to e…EPSS 0.35%5.1CVE-2026-3824Wellchoose organization portal system open redirect vulnerabilityIFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visit…EPSS 0.33%5.1CVE-2026-3825Wellchoose organization portal system cross-site scripting vulnerabilityIFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaSc…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2025-8912), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.