CVE List

CVE-2025-46154

Critical 8.4

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

Published June 3, 2025.

Affected software

Get alerts for Foxcms Foxcms

Reference links