VYPR
Medium severity6.5OSV Advisory· Published Dec 22, 2025· Updated Jun 17, 2026

CVE-2025-67436

CVE-2025-67436

Description

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Pluxml/PluxmlOSV3 versions
    5.4, 5.5, 5.6, …+ 2 more
    • (no CPE)range: 5.4, 5.5, 5.6, …
    • cpe:2.3:a:pluxml:pluxml:5.8.22:*:*:*:*:*:*:*
    • (no CPE)range: = 5.8.22

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.