References https://nvd.nist.gov/vuln/detail/CVE-2025-8772 https://www.redpacketsecurity.com/cve_alert_cve-2025-8772/ https://vulners.com/search/vendors/nukeviet/products/nukeviet https://app.opencve.io/cve/?vendor=nukeviet https://cve.imfht.com/detail/CVE-2025-8772 https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/cve-2025-8772 https://access.redhat.com/security/cve/cve-2025-8772 https://nukeviet.vn/vi/news/nhom-phat-trien/thong-tin-chinh-thuc-ve-cve-nukeviet-cms-851.html
Related VulnerabilitiesPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-28141: NextGEN Gallery <= 4.2.3 - Reflected Cross-Site ScriptingPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-34234: CtrlPanel <= 1.1.1 - Remote Code ExecutionPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-41456: Bludit CMS <= 3.20.0 - Cross-Site ScriptingPoCCVE-2026-41679: Paperclip - Remote Code ExecutionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal