CVE-2025-10353: Melis Technology Melis Platform

Critical severity, CVSS 9.3. EPSS: 2.7% chance of exploitation in the next 30 days.

File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' using the 'mcsdetail_img' parameter.

Affected products

Published 2025-10-08. Last modified 2026-10-08.