CVE-2025-45855: Erupt
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.
Affected products
- Erupt Erupt: up to and including 1.12.19
Published 2025-06-03. Last modified 2026-06-17.