VYPR

Pocketvj Control Panel Firmware

by Magdesign

CVEs (2)

  • CVE-2025-63334CriNov 5, 2025
    risk 0.64cvss 9.8epss 0.01

    PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote…

  • CVE-2025-45326MedSep 23, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.