CVE-2025-10544: Avepoint Compliance Guardian
High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Unrestricted file upload vulnerability in DocAve 6.13.2, Perimeter 1.12.3, Compliance Guardian 4.7.1, and earlier versions, allowing administrator users to upload files without proper validation. An attacker could exploit this vulnerability by uploading malicious files that compromise the system. In addition, it is vulnerable to Path Traversal, which allows files to be written to arbitrary directories within the web root.
Affected products
- Avepoint Compliance Guardian: before 4.7.1 (fixed in 4.7.1)
- Avepoint Docave: version 6.13.2 only
- Avepoint Perimeter: version 1.12.3 only
Published 2025-09-26. Last modified 2026-06-17.