ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.
We have discovered 956 live websites that are affected by CVE-2025-60790.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 956 live websites (100% of ProcessWire install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 52 versions ( 95% of all versions) |
| 167 websites | |
| 312 websites | |
| 137 websites | |
| 48 websites | |
| 46 websites | |
| 34 websites | |
| 28 websites | |
| 21 websites | |
| 20 websites | |
| 19 websites |
| .com | 288 websites |
| .de | 234 websites |
| .co.uk | 93 websites |
| .at | 45 websites |
| .nl | 44 websites |
| .org | 25 websites |
| .org.uk | 25 websites |
| .ch | 17 websites |
| .be | 16 websites |
| .it | 16 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.fr | ***,*** | ||
| **********************.com | ***,*** | ||
| ********.***.uk | ***,*** | ||
| ******.com | ***,*** | ||
| **********.de | ***,*** | ||
| *******************.***.uk | ***,*** | ||
| ***.**.at | ***,*** | ||
| ******.com | ***,*** | ||
| *********.com | ***,*** | ||
| *****************.com | ***,*** |
FAQ