CVE Feed

    Dashboard / CVE / CVE-2025-65271

    CVE-2025-65271

    Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that render untrusted user input, potentially enabling privilege escalation to an administrative account. Fixed in Azuriom 1.2.7.

    Published:Dec 8, 2025
    Last Modified:Dec 12, 2025
    EPS:Dec 8, 2025
    EPSS Score:0.00051
    CVSS Score:8.8

    Affected Products

    Vendor
    Azuriom
    Product
    Azuriom

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High