Get real-time updates on Telegram
CVE-2025-11631: docsys through 2.02.36 (inclusive); +1 more affected products
CVE-2025-11631. CVSS 3.1 base score 9.1 (CRITICAL, NVD). EPSS 0.00803 (percentile 0.55279), scored 2026-10-06.
Affected technology
docsys · through 2.02.36 (inclusive)
docsys project
DocSys · 2.02.0, 2.02.1, 2.02.2, 2.02.3, 2.02.4, 2.02.5, 2.02.6, 2.02.7, 2.02.8, 2.02.9, 2.02.10, 2.02.11, 2.02.12, 2.02.13, 2.02.14, 2.02.15, 2.02.16, 2.02.17, 2.02.18, 2.02.19, 2.02.20, 2.02.21, 2.02.22, 2.02.23, 2.02.24, 2.02.25, 2.02.26, 2.02.27, 2.02.28, 2.02.29, 2.02.30, 2.02.31, 2.02.32, 2.02.33, 2.02.34, 2.02.35, 2.02.36
RainyGao
Description’s affected range: up to 2.02.36
Component: Not specified by the source
File: /Doc/deleteDoc.do
Attack conditions (VulDB, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
VulDB’s CVSS 4.0 assessment (base score 2.1/10) rates confidentiality impact as none; integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-22
- CCR priority
- 36.6 /100 (P4)
- CVSS 3.1
- 9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H · NVD
- EPSS
- 0.00803 · percentile 0.55378 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-11631.html