CVE-2025-45529: Sscms Siteserver CMS

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

Affected products

  • Sscms Siteserver CMS: version 7.3.1 only

Published 2025-05-27. Last modified 2026-06-17.