CVE-2019-25574: Njtech Greencms

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

Affected products

  • Njtech Greencms: from 2.1.0612, up to and including 2.3.0603

Published 2026-03-21. Last modified 2026-06-17.