CVE-2022-25485

High PUBLISHED

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

Vendor: CuppaCMS Product: CuppaCMS

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.8 High EPSS 7.9%

At a Glance

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

php nuclei_scanner
CVE Published
Mar 15, 2022
Exploitation Reported
Jun 15, 2026
CVSS
7.8 High
EPSS
7.9%
Low complexity Unauthenticated

CVE References