Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13827

Опубликовано: 02 дек. 2025
Источник: nvd
EPSS Низкий

Описание

Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not restricted. ImpactIf the media folder is not restricted from running files this can lead to a remote code execution.

EPSS

Процентиль: 57%
0.00344
Низкий

Дефекты

CWE-434

Связанные уязвимости

github
2 месяца назад

GrapesJsBuilder File Upload allows all file uploads

EPSS

Процентиль: 57%
0.00344
Низкий

Дефекты

CWE-434