Unrated severityNVD Advisory· Published Dec 15, 2025· Updated Apr 7, 2026
Perch CMS 3.2 Remote Code Execution via Unrestricted File Upload
CVE-2023-53889
Description
Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51620mitreexploit
- www.vulncheck.com/advisories/perch-cms-remote-code-execution-via-unrestricted-file-uploadmitrethird-party-advisory
- grabaperch.commitreproduct
News mentions
0No linked articles in our index yet.