CVE-2025-29306
97Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 46%
from disclosure to weapon0 days
Published on NVDMar 27
1st PoCMar 25
VulnCheck+72d
exploitation probability
46%top 1% of all CVEs
observed exploitation
yesVulnCheck
15 public exploit(s)
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 15
exploitdbwww.exploit-db.com/exploits/52267unverifiedgithubgithub.com/Mattb709/CVE-2025-29306-PoC-FoxCMS-RCE★ 5githubgithub.com/verylazytech/CVE-2025-29306★ 2githubgithub.com/mantanhacker/Mass-CVE-2025-29306★ 1githubgithub.com/inok009/FOXCMS-CVE-2025-29306-POC★ 1githubgithub.com/congdong007/CVE-2025-29306_poc★ 0githubgithub.com/somatrasss/CVE-2025-29306★ 0githubgithub.com/amalpvatayam67/day06-foxcms-rce★ 0vulncheckvulncheck.com/xdb/fdb3778a15e6unverifiedvulncheckvulncheck.com/xdb/0082cb79902cunverifiedvulncheckvulncheck.com/xdb/a8cc5d1286f1unverifiedvulncheckvulncheck.com/xdb/90e157288eceunverifiedvulncheckvulncheck.com/xdb/1d01279c9a0aunverifiedvulncheckvulncheck.com/xdb/41be94a45a47unverifiedvulncheckvulncheck.com/xdb/5b0a1ca087dbunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.