CVE-2025-8116: Reflected XSS in PAD CMS
PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8116?
CVE-2025-8116 is considered a high severity vulnerability due to its potential for arbitrary JavaScript execution in a victim's browser.
How do I fix CVE-2025-8116?
To fix CVE-2025-8116, you should apply the latest security patch provided by PAD CMS for all affected templates.
What functionality is affected by CVE-2025-8116?
CVE-2025-8116 affects the printing and save to PDF functionalities of PAD CMS.
Who is at risk from CVE-2025-8116?
Users of PAD CMS are at risk from CVE-2025-8116 as it allows attackers to execute malicious scripts in the users' browsers.
Which templates are vulnerable to CVE-2025-8116?
All three templates of PAD CMS—www, bip, and www+bip—are vulnerable to CVE-2025-8116.