CVE-2025-60790

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.


We have discovered 956 live websites that are affected by CVE-2025-60790.

Run a Free Instant Scan




Affected Software

Product  ProcessWire
Category Content Management System
Vulnerable Domains956 live websites (100% of ProcessWire install base)
Vulnerable Versions
  • from 0 through 3.0.246
Vulnerable Versions Count52 versions ( 95% of all versions)



Details

  • Published - Oct 21, 2025
  • Updated - Oct 27, 2025

Website Distribution by Country

Number of websites using CVE-2025-60790
United States167 websites



Germany312 websites
GB137 websites
Austria48 websites
Netherlands46 websites
France34 websites
Italy28 websites
Russia21 websites
Canada20 websites
Singapore19 websites

Website Distribution by TLD

Number of websites using CVE-2025-60790
.com288 websites
.de234 websites
.co.uk93 websites
.at45 websites
.nl44 websites
.org25 websites
.org.uk25 websites
.ch17 websites
.be16 websites
.it16 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-60790

Top websites that are affected by CVE-2025-60790. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.fr France***,***
**********************.com United States***,***
********.***.uk GB***,***
******.com United States***,***
**********.de Germany***,***
*******************.***.uk GB***,***
***.**.at Austria***,***
******.com United States***,***
*********.com France***,***
*****************.com United States***,***
See full domain list

FAQ

A total of 956 websites have been identified as vulnerable to CVE-2025-60790, based on global website indexing conducted by WebTechSurvey.
The ProcessWire is affected by the CVE-2025-60790 vulnerability.
ProcessWire versions up to 3.0.246 are vulnerable to CVE-2025-60790.
CVE-2025-60790 is resolved in version 3.0.246 of ProcessWire.