CVE-2025-32151
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 98
Summary
CVE-2025-32151 signifies a vulnerability in Sven Lehnert BuddyForms, where an Improper Control of Filename for Include/Require Statement exists, leading to a PHP Local File Inclusion issue. This flaw, present from an undisclosed version up to 2.8.15, allows attackers to manipulate files and potentially execute malicious code on a targeted system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.