CVE-2025-54962: Thiagoralves OpenPLC v3
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.
Affected products
- Thiagoralves OpenPLC v3
Published 2025-08-04. Last modified 2026-06-17.