CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-25785

Critical · CVSS 9.1

JizhiCMS — Server-Side Request Forgery (SSRF)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-918

Description

JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.

Search profile — drives PoC discovery

Symbols PluginsController.php\c\PluginsController.php
Keywords CVE-2025-25785JizhiCMSJizhiCMS SSRFPluginsController SSRFJizhiCMS v2.5.4intranet scan SSRFjizhicms PoC
Versions: v2.5.4

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z