Path Traversal Vulnerability in PowerCMS by PowerCMS
CVE-2025-46359

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
31 July 2025

What is CVE-2025-46359?

A path traversal vulnerability has been identified in the backup and restore features of multiple versions of PowerCMS. This flaw allows product administrators to execute arbitrary code by restoring a crafted backup file. This issue emphasizes the importance of securing backup functionalities within content management systems to prevent unauthorized code execution, potentially compromising server integrity and data confidentiality.

Affected Version(s)

PowerCMS 6.7 and earlier (PowerCMS 6.x series)

PowerCMS 5.3 and earlier (PowerCMS 5.x series)

PowerCMS 4.6 and earlier (PowerCMS 4.x series)

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.