CVE-2025-45529: Sscms Siteserver CMS
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
Affected products
- Sscms Siteserver CMS: version 7.3.1 only
Published 2025-05-27. Last modified 2026-06-17.