{"id":"GHSA-9p44-q66p-xm6p","summary":"ProcessWire CMS vulnerable to resource-exhaustion Denial of Service","details":"ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.","aliases":["CVE-2025-60790"],"modified":"2025-10-27T20:21:46.981895Z","published":"2025-10-21T18:30:35Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-21T21:04:22Z","nvd_published_at":"2025-10-21T18:15:36Z","cwe_ids":["CWE-400","CWE-409"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60790"},{"type":"WEB","url":"https://github.com/processwire/processwire-issues/issues/2120"},{"type":"WEB","url":"https://github.com/NomanProdhan/security-vulnerability-research/tree/master/CVE-2025-60790"},{"type":"PACKAGE","url":"https://github.com/processwire/processwire"}],"affected":[{"package":{"name":"processwire/processwire","ecosystem":"Packagist","purl":"pkg:composer/processwire/processwire"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.246"}]}],"versions":["3.0.123","3.0.148","3.0.164","3.0.165","3.0.184","3.0.200","3.0.210","3.0.226","3.0.227","3.0.244","3.0.246","3.0.34","3.0.35","3.0.36","3.0.39","3.0.41","3.0.42","3.0.61","3.0.62","3.0.96","3.0.98"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-9p44-q66p-xm6p/GHSA-9p44-q66p-xm6p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"}]}