CVE-2025-30580

CVSS 3.1 Score 10 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 94

Summary

CVE-2025-30580 is a Code Injection vulnerability affecting NotFound DigiWidgets Image Editor from versions n/a through 1.10. An attacker can exploit this Improper Control of Code Generation issue to include remote code, leading to potential security breaches. This vulnerability allows an attacker to inject malicious code into the image editor, posing a serious threat to the integrity and confidentiality of affected systems. Successful exploitation could result in unauthorized access, data theft, or system takeover. Users of the DigiWidgets Image Editor are advised to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share