Remote Code Execution Vulnerability in PAD CMS by PAD Technologies
CVE-2025-8120
10CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-8120?
The PAD CMS platform features a severe vulnerability stemming from a client-controlled permission check in its file upload functionality. This flaw permits unauthenticated remote attackers to upload arbitrary files of any type and extension, bypassing normal restrictions. If exploited, this can lead to remote code execution, posing significant security risks. The vulnerability impacts all three templates of PAD CMS: www, bip, and ww+bip. Note that this product is no longer supported and the vendor will not provide patches for this issue.
Affected Version(s)
PAD CMS 0 <= 1.2.1