CVE-2025-30091: Tiny Moxiemanager PHP
Critical severity, CVSS 9.4. EPSS: 0.8% chance of exploitation in the next 30 days.
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into config.php, and InstallCommand is available after an installation has completed.
Affected products
- Tiny Moxiemanager PHP: before 4.0.0 (fixed in 4.0.0)
Published 2025-03-25. Last modified 2026-06-17.