Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29730 | WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without sufficient validation, allowing the attacker to force internal or external HTTP requests. |
| Link | Providers |
|---|---|
| https://github.com/thawphone/CVE-2025-57055 |
|
Tue, 23 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:wondercms:wondercms:3.5.0:*:*:*:*:*:*:* |
Thu, 18 Sep 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wondercms
Wondercms wondercms |
|
| Vendors & Products |
Wondercms
Wondercms wondercms |
Wed, 17 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Wed, 17 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated administrator can supply a malicious URL via the pluginThemeUrl POST parameter. The server fetches the provided URL using curl_exec() without sufficient validation, allowing the attacker to force internal or external HTTP requests. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-17T17:23:49.120Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57055
Updated: 2025-09-17T17:21:08.934Z
Status : Analyzed
Published: 2025-09-17T15:15:43.667
Modified: 2025-09-23T15:44:52.297
Link: CVE-2025-57055
No data.
OpenCVE Enrichment
Updated: 2025-09-18T12:41:52Z
EUVD