๐Ÿ” CVE Alert

CVE-2025-15262

MEDIUM 4.7

BiggiDroid Simple PHP CMS Site Logo edit.php unrestricted upload

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component Site Logo Handler. Performing a manipulation of the argument image results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CWE CWE-434 CWE-284
Vendor biggidroid
Product simple php cms
Published Dec 30, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for biggidroid simple php cms

Be the first to know when new medium vulnerabilities affecting biggidroid simple php cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

BiggiDroid / Simple PHP CMS
1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.338656 vuldb.com: https://vuldb.com/?ctiid.338656 vuldb.com: https://vuldb.com/?submit.725815 gitee.com: https://gitee.com/shanyaohei/black-yam/issues/IDGML9

Credits

๐Ÿ” heishanyao (VulDB User)