CVE-2025-65657 – FeehiCMS Remote Code Execution via Unrestricted File Upload

The following table lists the changes that have been made to the
CVE-2025-65657 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Dec. 02, 2025

    Action Type Old Value New Value
    Added Description FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).
    Added Reference https://github.com/kiwi865/CVEs/blob/main/CVE-2025-65657.md
    Added Reference https://github.com/liufee/cms/issues/78
Share the Post:

Related Posts