CVE-2025-25772: Ujcms Jspxcms
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
Affected products
- Ujcms Jspxcms: from 9.0.0, up to and including 9.5.0
Published 2025-02-21. Last modified 2026-06-17.