References https://nvd.nist.gov/vuln/detail/CVE-2025-8772 https://www.redpacketsecurity.com/cve_alert_cve-2025-8772/ https://vulners.com/search/vendors/nukeviet/products/nukeviet https://app.opencve.io/cve/?vendor=nukeviet https://cve.imfht.com/detail/CVE-2025-8772 https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-8772 https://access.redhat.com/security/cve/cve-2025-8772 https://nukeviet.vn/vi/news/nhom-phat-trien/thong-tin-chinh-thuc-ve-cve-nukeviet-cms-851.html
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2024-57728: SimpleHelp <= 5.5.7 - Arbitrary File UploadPoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2026-12227: Visual Composer <= 45.16.0 - Unauthenticated LFIPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-49060: Hippoo Mobile App for WooCommerce - Broken Access ControlPoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion