CVE-2023-53889: Grabaperch Perch

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.

Affected products

Published 2025-12-15. Last modified 2026-06-17.