Vulnerability advisory

CVE-2025-60790

Research by Md. Moniruzzaman Prodhan October 21, 2025
Overview

Summary

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

Risk profile

CVSS assessment

6.5 · M E D I U M
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack vector
N E T W O R K
Complexity
L O W
Privileges
L O W
User interaction
N O N E
Scope
U N C H A N G E D
Confidentiality
N O N E
Integrity
N O N E
Availability
H I G H
Classification

Weaknesses

  • Uncontrolled Resource Consumption CWE-400
Configurations

Affected products

1 configuration
Vulnerable match
cpe:2.3:a:processwire:processwire:*:*:*:*:*:*:*:*
Through 3.0.246 inclusive
Further reading

References

2 sources
  1. github.com https://github.com/NomanProdhan/security-vulnerability-research/tree/master/CVE-2025-60790 Exploit Third Party Advisory
  2. github.com https://github.com/processwire/processwire-issues/issues/2120 Exploit Issue Tracking Vendor Advisory