CVE-2025-60790 - ProcessWire CMS Zip File Extraction Denial of Service
CVE ID : CVE-2025-60790
Published : Oct. 21, 2025, 6:15 p.m. | 1 hour, 29 minutes ago
Description : ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 21, 2025, 6:15 p.m. | 1 hour, 29 minutes ago
Description : ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...