CVE-2025-28357

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A CRLF injection vulnerability in Neto CMS v6.313.0 through v6.314.0 allows attackers to execute arbitrary code via supplying a crafted HTTP request.

Published 2025-10-01. Last modified 2026-07-05.