CVE-2025-67436 - PluXml CMS Remote Code Execution Vulnerability

CVE-2025-67436 - PluXml CMS Remote Code Execution Vulnerability

CVE ID : CVE-2025-67436 Published : Dec. 22, 2025, 10:16 p.m. | 1 hour, 46 minutes ago Description : Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php). Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 22, 2025
Affected Product: PHP
Impact: Remote Code Execution

Source: Telegram CVE Monitor