CVE-2025-32510

CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/...

Affects 0 products across 1 vendor.

BCS7.24
CVSS 3.110.0
EPSS0.4%
Percentile34th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Ovatheme Events Manager allows for the unrestricted upload of files with dangerous types, enabling attackers to upload and execute malicious files on the server.

BSID: BS-2025-GLOBAL-254090-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-32510?
A critical vulnerability in Ovatheme Events Manager allows for the unrestricted upload of files with dangerous types, enabling attackers to upload and execute malicious files on the server.
What is the CVSS score for CVE-2025-32510?
CVE-2025-32510 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2025-32510 actively exploited?
No confirmed active exploitation of CVE-2025-32510 as of 2026-05-30.
How do I remediate CVE-2025-32510?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-32510?
CVE-2025-32510 affects: Files.
Vulnerability Details
CVE IDCVE-2025-32510
BSIDBS-2025-GLOBAL-254090-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-06-17
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager allows Using Malicious Files.This issue affects Ovatheme Events Manager: from n/a through <= 1.8.4.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by uploading a malicious file, such as a PHP script, through the file upload functionality of the Ovatheme Events Manager plugin. Once uploaded, the attacker can execute the malicious file, leading to remote code execution and potential full control of the server.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Files &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 410 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash205f262e055ba727639e48e695e4d2230c01982d8f0f1bf167e56d4ea40f5ea7e68b6d9e0c2b576e147223aea23e4a57102ae0aacb2518e2120abfb38c39d2d7
Related CVEs affecting Files
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-2025-48148 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper ... CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →