CVE Vulnerabilities

CVE-2025-14731

Incomplete Filtering of Special Elements

Published: Dec 16, 2025 | Modified: Dec 24, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

Weakness

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Affected Software

NameVendorStart VersionEnd Version
CtcmsCtcms_project*2.1.2 (including)

References