logo

Vulnerabilities in PAD CMS software

ID: 60fe07bc-8e51-52aa-8169-9131c9e22270

STIX ID: report--60fe07bc-8e51-52aa-8169-9131c9e22270

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2025-09-30

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska coordinated disclosure of nine vulnerabilities in PAD CMS (affecting all versions through 1.2.1). The issues include unrestricted file upload flaws enabling remote code execution, blind SQL injection, reflected XSS, CSRF, a password-recovery initialization bug allowing account takeover, and a client-side brute-force bypass; the product is end-of-life and no vendor patches will be published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.