{"id":"CVE-2025-61668","title":"Volto is a ReactJS-based frontend for the Plone Content Management System","summary":"Volto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS se…","severity":"none","cwe":["CWE-476","CWE-754"],"published":"2025-10-02","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:10:00.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-61668","references":[{"url":"http://github.com/plone/volto/releases/tag/18.27.2","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/commit/58d9f82d2d50ca9a87edbe16fed91762e57c109c","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/pull/7412","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/pull/7413","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/releases/tag/16.34.1","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/releases/tag/17.22.2","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/releases/tag/19.0.0-alpha.6","label":"security-advisories@github.com"},{"url":"https://github.com/plone/volto/security/advisories/GHSA-m8rj-ppph-mj33","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00437,"epssPercentile":0.35993,"ingestedAt":"2026-10-08T23:16:47.361Z","slug":"CVE-2025-61668","body":"## Overview\n\nVolto is a ReactJS-based frontend for the Plone Content Management System. Versions 16.34.0 and below, 17.0.0 through 17.22.1, 18.0.0 through 18.27.1, and 19.0.0-alpha.1 through 19.0.0-alpha.5, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. This issue is fixed in versions 16.34.1, 17.22.2, 18.27.2 and 19.0.0-alpha.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}