CVE-2025-60947
Census CSWeb arbitrary file upload
CVSS Score
8.8
EPSS Score
0.2%
EPSS Percentile
41th
Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.
| CWE | CWE-434 |
| Vendor | census |
| Product | csweb |
| Published | Mar 23, 2026 |
| Last Updated | Mar 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for census csweb
Be the first to know when new high vulnerabilities affecting census csweb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Census / CSWeb
8.0.1 < 8.1.0 alpha
References
github.com: https://github.com/hx381/cspro-exploits github.com: https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91 cve.org: https://www.cve.org/CVERecord?id=CVE-2025-60947 raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json