Vulnerabilities > Ipwsystems

DATE CVE VULNERABILITY TITLE RISK
2025-04-28 CVE-2025-46661 Code Injection vulnerability in Ipwsystems Metazo
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because smartyValidator.php enables the attacker to provide template expressions, aka Server-Side Template-Injection.
network
low complexity
ipwsystems CWE-94
critical
9.8