CVE Database
/

CVE-2025-14532

Back to search

CVE-2025-14532

Published: Mar 2, 2026

Modified: Mar 2, 2026

PUBLISHED

Description

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

VendorProductVersions

Studio Fabryka

DobryCMS

affected
1.0 - <= 1.*
affected
2.0 - <= 2.*
affected
5.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now