CVE-2025-67436
EUVD-2025-20475822.12.2025, 22:16
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pluxml | pluxml | 5.8.22 |
𝑥
= Vulnerable software versions
Ubuntu Releases