CVE-2023-29689: Pyrocms

Critical severity, CVSS 9.8. EPSS: 53.5% chance of exploitation in the next 30 days.

PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

Affected products

Published 2023-08-04. Last modified 2026-06-17.