Remote Code Execution Vulnerability in PAD CMS by PAD CMS Development
CVE-2025-7063
10CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-7063?
A concerning vulnerability in PAD CMS's file upload feature arises from a client-controlled permission check parameter. This flaw facilitates unauthorized remote attackers to upload files of any type and extension without restrictions. The potential for executing harmful code creates a significant risk, particularly affecting all three templates: www, bip, and ww+bip. Notably, PAD CMS is no longer supported by the vendor, meaning no patches will be available to address this serious issue.
Affected Version(s)
PAD CMS 0 <= 1.2.1