CVE-2025-14729

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
15/12/2025
Last modified:
18/12/2025

Description

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ctcms_project:ctcms:*:*:*:*:*:*:*:* 2.1.2 (including)