# CVE-2025-47916

## Summary

- **CVE ID:** CVE-2025-47916
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1336
- **Published:** May 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.

## Affected Products

- invisioncommunity — Invision Power Board (5.0.0)

## References

- [CNA](https://invisioncommunity.com/release-notes-v5/507-r41/)
- [CNA](https://karmainsecurity.com/KIS-2025-02)
- [CVE](http://seclists.org/fulldisclosure/2025/May/4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 83.73%
- **EPSS Percentile:** 99.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._