Skip to content
Medium Published: Dec 15, 2025

CVE-2025-14729

4.7 CVSS Score Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Export CVE-2025-14729 Data:
Share:
Link copied!

Description

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS Vector Details

Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability Low

Weaknesses (CWE)

  • CWE-74

CVE History Timeline

Dec 15, 2025 23:15 New CVE Received