CVE-2025-12331
A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/matthewdeaves/willow/issues/132, https://vuldb.com/?ctiid.330116, https://vuldb.com/?id.330116, https://vuldb.com/?submit.674439, https://www.youtube.com/watch?v=zacD0QLUYs8
