CVE-2025-67436: Pluxml
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).
Affected products
- Pluxml Pluxml: version 5.8.22 only
Published 2025-12-22. Last modified 2026-06-17.