A vulnerability identified as CVE-2022-25497, affecting CuppaCMS, has been listed in VulnCheck's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. However, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has not included this flaw in its own KEV catalog, nor has the European Union Agency for Cybersecurity (ENISA) through its European Vulnerability Database (EUVD).
The vulnerability was initially reserved on February 21, 2022, and publicly disclosed on March 15, 2022. It was first reported as exploited on September 17, 2026, approximately 1647 days after its initial disclosure. This information comes from a single KEV source, VulnCheck, with CIRCL also mirroring this listing. There is no independent corroboration from a second catalog regarding its exploitation.
Public evidence of exploitation was reported on September 17, 2026, via previdian.com, which is cited by both VulnCheck and CIRCL. The severity of CVE-2022-25497 is currently listed as "none" in its CVSS score, and its Exploit Prediction Scoring System (EPSS) percentile is 89.2%, with a 3.6% probability of exploitation.
The CuppaCMS vulnerability is described as an arbitrary file deletion flaw. Specifically, the `delete_file.php` component in CuppaCMS version 1.0, when handling the `url` parameter, is susceptible to directory traversal. This allows an unauthenticated attacker to delete arbitrary files on the server. The issue was initially reported by a security researcher on February 21, 2022.
While the vulnerability's exploitation is confirmed by VulnCheck, the absence of its inclusion in CISA's KEV means it does not currently trigger mandatory remediation requirements for U.S. federal civilian executive branch agencies. Organizations using CuppaCMS version 1.0 are advised to review their systems for potential compromise and apply any available patches or mitigation strategies.






