← Browse CVEs
CVE-2025-49704
High · CVSS 8.8EPSS 99.9%CISA KEVCWE-94 · Code Injection
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
References
Published
Community ground truth
Community verdict
2 verdictsNot a real issue
to add your verdict.
Community real-world severity: Critical (Critical 2) — CVSS base score 8.8
Practitioners rate this higher than its CVSS — treat with extra caution.
Field notes & remediation
Verdicts are the quick signal — notes are the evidence and fixes behind them.
No notes yet — be the first to share what you saw or a fix that worked.