CVE-2025-65840: CSRF
Published Dec 1, 2025
·Updated
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
Affected Software
2 affected components
PublicCMS PublicCMS
PublicCMS PublicCMS=5.202506.b
Event History
Dec 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65840?
CVE-2025-65840 has a medium severity rating due to its potential for exploitation through Cross Site Request Forgery (CSRF).
2
How do I fix CVE-2025-65840?
To mitigate CVE-2025-65840, implement CSRF tokens in forms and ensure proper validation for all state-changing actions in PublicCMS.
3
What kind of attacks can CVE-2025-65840 facilitate?
CVE-2025-65840 enables attackers to perform unauthorized actions on behalf of authenticated users through CSRF attacks.
4
Is CVE-2025-65840 present in all versions of PublicCMS?
CVE-2025-65840 specifically affects PublicCMS V5.202506.b and potentially other unpatched versions.
5
What steps can I take to protect my application from CVE-2025-65840?
To protect against CVE-2025-65840, ensure that all user actions requiring authentication are properly guarded with CSRF protection measures.