CVE-2025-68436 | Craft CMS up to 4.16.16/5.8.20 User Profile Photo information disclosure (GHSA-53vf-c43h-j2x9 / EUVD-2026-0846)
A vulnerability was found in Craft CMS up to 4.16.16/5.8.20 and classified as problematic. This affects an unknown part of the component User Profile Photo Handler. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2025-68436. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.