CVE-2023-29689: Pyrocms
Critical severity, CVSS 9.8. EPSS: 53.5% chance of exploitation in the next 30 days.
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
Affected products
- Pyrocms Pyrocms: version 3.9 only
Published 2023-08-04. Last modified 2026-06-17.