CVE-2025-67436
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inj
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).
MEDIUM · CVSS 6.5
EPSS 0.00179
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0