# CVE-2025-54752

## Summary

- **CVE ID:** CVE-2025-54752
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L)
- **CWE:** CWE-1236
- **Published:** Jul 31, 2025
- **Last Modified:** Mar 12, 2026

## Description

Multiple versions of PowerCMS improperly neutralize formula elements in a CSV file.  If a product user creates a malformed entry and a victim user downloads it as a CSV file and opens it in the user's environment, the embedded code may be executed.

## Affected Products

- Alfasado Inc. — PowerCMS (6.7 and earlier (PowerCMS 6.x series))
- Alfasado Inc. — PowerCMS (5.3 and earlier (PowerCMS 5.x series))
- Alfasado Inc. — PowerCMS (4.6 and earlier (PowerCMS 4.x series))

## References

- [CNA](https://www.powercms.jp/news/release-powercms-671-531-461.html)
- [CNA](https://jvn.jp/en/vu/JVNVU93412964/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 15.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._