CVE-2025-46154: Foxcms
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
Affected products
- Foxcms Foxcms: version 1.25 only
Published 2025-06-03. Last modified 2026-06-17.