CVE-2025-67436

Publication date

2025-12-22 00:00:00

Family

mitre

State

PUBLISHED

Description

Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).