peter bassill · operator
$ cve CVE-2025-47916 JSON

CVE-2025-47916 EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 83.7% (pctl 100)

Patch early

A public exploit exists.

Description

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS83.73% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-1336
On CISA KEVno
Public exploityes
Published2025-05-16
Last modified2026-06-17

Affected (1)

VendorProduct
invisioncommunityinvisioncommunity

Public exploits

SourceTitleDate
exploit-dbInvision Community 5.0.6 - Remote Code Execution (RCE)2025-05-18

References

→ the Explorer  ·  watch your stack  ·  NVD