CVE-2025-29993: Alfasado Inc Powercms 4.x Series

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The affected versions of PowerCMS allow HTTP header injection. This vulnerability can be leveraged to direct the affected product to send email with a tampered URL, such as password reset mail.

Affected products

Published 2025-03-27. Last modified 2026-06-17.