CVE-2025-6001: Virtuemart

High severity, CVSS 8.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF request which will allow unrestricted file upload into the VirtueMart media manager.

Affected products

  • Virtuemart Virtuemart: from 3.0.0, before 4.4.10 (fixed in 4.4.10)

Published 2025-06-11. Last modified 2026-06-17.