CVE-2025-44022: Code Injection
Published May 12, 2025
·Updated
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.
Affected Software
2 affected components
Vvveb CMS
Vvveb vvveb=1.0.6
Remediation
Event History
May 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44022?
CVE-2025-44022 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2025-44022?
To fix CVE-2025-44022, update vvveb CMS to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2025-44022?
CVE-2025-44022 affects users of vvveb CMS version 1.0.6.
4
What kind of vulnerability is CVE-2025-44022?
CVE-2025-44022 is a remote code execution vulnerability in the plugin mechanism of vvveb CMS.
5
Can CVE-2025-44022 be exploited by unauthenticated users?
Yes, CVE-2025-44022 can be exploited by remote attackers without authentication.