CVE-2023-25264: Docmosis Tornado

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Docmosis Tornado prior to version 2.9.5. An unauthenticated attacker can bypass the authentication check filter completely by introducing a specially crafted request with relative path segments.

Affected products

  • Docmosis Tornado: before 2.9.5 (fixed in 2.9.5)

Published 2023-02-28. Last modified 2026-06-17.