CVE-2025-14731
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/12/2025
Last modified:
16/12/2025
Description
A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://note-hxlab.wetolink.com/share/Ros8ZIeCLQrN
- https://note-hxlab.wetolink.com/share/U6cnRoRfn09r
- https://vuldb.com/?ctiid_336488=
- https://vuldb.com/?id_336488=
- https://vuldb.com/?submit_707106=
- https://vuldb.com/?submit_707107=
- https://note-hxlab.wetolink.com/share/Ros8ZIeCLQrN
- https://note-hxlab.wetolink.com/share/U6cnRoRfn09r



