Home

Description

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).

PUBLISHED Reserved 2025-12-08 | Published 2025-12-22 | Updated 2025-12-22 | Assigner mitre

References

github.com/pluxml/PluXml

github.com/RajChowdhury240/CVE-2025-67435/

cve.org (CVE-2025-67436)

nvd.nist.gov (CVE-2025-67436)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.