CVE-2025-45326: Magdesign Pocketvj Control Panel Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.

Affected products

  • Magdesign Pocketvj Control Panel Firmware: version 3.9.1 only

Published 2025-09-23. Last modified 2026-06-17.