CVE-2025-60790 is a denial-of-service vulnerability affecting ProcessWire CMS version 3.0.246. A low-privileged user with 'lang-edit' permissions can upload a specially crafted ZIP file to the Language Support feature, which is automatically extracted without proper validation. This uncontrolled extraction can lead to resource exhaustion, effectively causing a denial of service. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and low privileges required, resulting in high availability impact. There is currently no evidence of active exploitation, nor are there any publicly available exploit modules or proof-of-concept code. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.246CPE matchmatch criteria | cpe:2.3:a:processwire:processwire:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.