AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-6967

HIGH · CVSS 8.7 EPSS 0.45%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-10 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.7. It affects Java.

CVE
CVE-2025-6967
Severity
HIGH
CVSS
8.7
EPSS
0.45%
Java

Original NVD Description

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass. This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.