CVE-2017-14958: Pivotx
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
Affected products
- Pivotx Pivotx: version 2.3.11 only
Published 2017-10-02. Last modified 2026-06-17.