This product is End-Of-Life and producent will not publish patches for this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31711 | PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability. |
| Link | Providers |
|---|---|
| https://cert.pl/posts/2025/09/CVE-2025-7063 |
|
Wed, 26 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Widzialni
Widzialni pad Cms |
|
| CPEs | cpe:2.3:a:widzialni:pad_cms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Widzialni
Widzialni pad Cms |
|
| Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pad
Pad pad Cms |
|
| Vendors & Products |
Pad
Pad pad Cms |
Tue, 30 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability. | |
| Title | Cross-Site Request Forgery in PAD CMS | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-09-30T19:14:50.548Z
Reserved: 2025-07-24T14:23:32.250Z
Link: CVE-2025-8119
Updated: 2025-09-30T19:14:44.368Z
Status : Analyzed
Published: 2025-09-30T11:37:44.167
Modified: 2025-11-26T14:40:55.727
Link: CVE-2025-8119
No data.
OpenCVE Enrichment
Updated: 2025-10-02T08:46:25Z
EUVD