CVE-2025-5497:
A critical vulnerability in slackero phpwcms versions up to 1.9.45 and 1.10.8 allows for remote deserialization attacks through the Feedimport Module.
Score
A numerical rating that indicates how dangerous this vulnerability is.
9.8Critical- Published Date:Jun 3, 2025
- CISA KEV Date:*No Data*
- Industries Affected:20
Threat Predictions
- EPSS Score:0.5
- EPSS Percentile:64%
Exploitability
- Score:3.9
- Attack Vector:NETWORK
- Attack Complexity:LOW
- Privileges Required:NONE
- User Interaction:NONE
- Scope:UNCHANGED
Impact
- Score:5.9
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:HIGH
Description Preview
A critical vulnerability in slackero phpwcms versions up to 1.9.45 and 1.10.8 allows for remote deserialization attacks through the Feedimport Module.
Overview
- **CVE ID**: CVE-2025-5497 - **Published Date**: June 3, 2025 - **Vulnerability Status**: Received - **Severity**: Critical - **Affected Components**: Feedimport Module in slackero phpwcms - **Vulnerable Versions**: Up to 1.9.45 and 1.10.8 - **Attack Vector**: Network - **Attack Complexity**: Low - **Privileges Required**: Low - **User Interaction**: None - **Impact**: Low confidentiality, integrity, and availability impact
Remediation
- To remediate the vulnerability CVE-2025-5497, it is strongly recommended that users upgrade their installations of slackero phpwcms to the following versions:
- **Upgrade to**: Version 1.9.46 or 1.10.9
- This upgrade addresses the deserialization vulnerability and mitigates the associated risks.
References
- 1. [GitHub - CVE Repository](https://github.com/3em0/cve_repo/blob/main/phpwcms/phar%20vulnerability%20in%20phpwcms.md)
- 2. [GitHub - phpwcms Release v1.10.9](https://github.com/slackero/phpwcms/releases/tag/v1.10.9)
- 3. [VulDB - CVE Details](https://vuldb.com/?ctiid.310912)
- 4. [VulDB - CVE Information](https://vuldb.com/?id.310912)
- 5. [VulDB - Submission](https://vuldb.com/?submit.577999)
- 6. [GitHub - CVE Repository (Duplicate)](https://github.com/3em0/cve_repo/blob/main/phpwcms/phar%20vulnerability%20in%20phpwcms.md)
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.