CVE-2025-52207: Miko Mikopbx

Critical severity, CVSS 9.9. EPSS: 1.6% chance of exploitation in the next 30 days.

PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.

Affected products

  • Miko Mikopbx: up to and including 2024.1.114

Published 2025-06-27. Last modified 2026-06-17.