Celonis develops process intelligence and automation software, with its Make Connector product serving as an integration component for workflow and data-pipeline scenarios. The durable signal centers on file-upload handling, where the connector has shown susceptibility to unrestricted file-type acceptance, a class of vulnerability common to integration and middleware products that accept external data sources. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Celonis over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6085HIGH The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and | Sep 4, 2025 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Celonis.
Media articles that mention a CVE ID that affects a product developed by Celonis — matched by CVE ID, not by vendor name.