CVE-2025-60790

Source
https://cve.org/CVERecord?id=CVE-2025-60790
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60790.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-60790
Aliases
Published
2025-10-21T18:15:36.630Z
Modified
2026-03-14T12:44:16.281368Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

References

Affected packages

Git / github.com/processwire/processwire

Affected ranges

Type
GIT
Repo
https://github.com/processwire/processwire
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.246"
        }
    ]
}

Affected versions

3.*
3.0.123
3.0.148
3.0.164
3.0.165
3.0.184
3.0.200
3.0.210
3.0.226
3.0.227
3.0.244
3.0.246
3.0.34
3.0.35
3.0.36
3.0.39
3.0.41
3.0.42
3.0.61
3.0.62
3.0.96
3.0.98

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60790.json"