CVE-2025-55046 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability affecting MuraCMS through version 10.1.10. Rated 8.1 CVSS, this flaw allows an unauthenticated attacker to permanently destroy all deleted content stored in the trash system. The vulnerability exploits a lack of CSRF token validation in the `cTrash.empty` function, enabling catastrophic and irreversible data loss if an authenticated administrator visits a crafted malicious webpage. There is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:murasoftware:mura_cms:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.