CVE-2025-54962: Thiagoralves OpenPLC v3

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.

Affected products

Published 2025-08-04. Last modified 2026-06-17.