PatchSiren

EmpireSoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW EmpireSoft CVE published 2026-01-02

CVE-2025-15423

A vulnerability was found in EmpireSoft EmpireCMS up to 8.0, impacting the CheckSaveTranFiletype function in e/class/connect.php, allowing unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Defenders should assess the vulnerability's impact on EmpireCMS [truncated]

MEDIUM EmpireSoft CVE published 2026-01-02

CVE-2025-15422

A flaw in EmpireSoft EmpireCMS up to 8.0 in the IP Address Handler causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. Defenders should assess exposure and potential impact of this flaw in EmpireSoft EmpireCMS up to 8.0, particul [truncated]