This product is End-Of-Life and producent will not publish patches for this vulnerability.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31714 | PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://cert.pl/posts/2025/09/CVE-2025-7063 |
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pad
Pad pad Cms |
|
| Vendors & Products |
Pad
Pad pad Cms |
Tue, 30 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability. | |
| Title | Reflected XSS in PAD CMS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-09-30T19:13:04.145Z
Reserved: 2025-07-24T13:38:01.739Z
Link: CVE-2025-8116
Updated: 2025-09-30T19:13:00.545Z
Status : Awaiting Analysis
Published: 2025-09-30T11:37:43.683
Modified: 2025-10-02T19:12:42.843
Link: CVE-2025-8116
No data.
OpenCVE Enrichment
Updated: 2025-10-02T08:46:26Z
EUVD