Resource-Exhaustion Vulnerability in ProcessWire CMS by ProcessWire
CVE-2025-60790
6.5MEDIUM
What is CVE-2025-60790?
A vulnerability in ProcessWire CMS 3.0.246 allows low-privileged users with lang-edit permissions to upload unchecked ZIP files to the Language Support feature. This ZIP file is subjected to auto-extraction without validation limits, potentially leading to resource exhaustion and Denial of Service conditions for the affected system.
