CVE-2025-24289: Ubiquiti Inc Ucrm Client Signup Plugin

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.

Affected products

  • Ubiquiti Inc Ucrm Client Signup Plugin: before 1.3.5 (fixed in 1.3.5)

Published 2025-06-29. Last modified 2026-06-17.