CVE-2025-69437: XSS

Published Feb 27, 2026
·
Updated

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered, resulting in issues such as credential theft, arbitrary API execution, and other security concerns. This vulnerability affects all file upload endpoint, including /cmsTemplate/save, /file/doUpload, /cmsTemplate/doUpload, /file/doBatchUpload, /cmsWebFile/doUpload, etc.

Affected Software

2 affected components
PublicCMS PublicCMS<v5.202506.d
PublicCMS PublicCMS<=5.202506.d

Event History

Feb 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-69437?

CVE-2025-69437 is classified as a high severity vulnerability due to its potential for stored XSS attacks.

2

How do I fix CVE-2025-69437?

To fix CVE-2025-69437, upgrade PublicCMS to a version later than v5.202506.d to ensure the vulnerability is patched.

3

What is the impact of CVE-2025-69437?

The impact of CVE-2025-69437 includes the potential execution of malicious JavaScript when a user views an uploaded PDF, leading to unauthorized actions or data exposure.

4

Who is affected by CVE-2025-69437?

Users of PublicCMS versions v5.202506.d and earlier are affected by CVE-2025-69437 due to the stored XSS vulnerability.

5

Can CVE-2025-69437 be exploited remotely?

Yes, CVE-2025-69437 can be exploited remotely if an attacker uploads a malicious PDF which then targets users viewing the document.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203