PT-2025-42618 · Unknown · Pluxml Cms

Published

2025-10-17

·

Updated

2025-10-22

·

CVE-2025-57567

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PluXml CMS (affected versions not specified)
Description A remote code execution (RCE) issue exists in PluXml CMS within the theme editor functionality. The flaw is located in the minify.php file, found in the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code through the admin panel, allowing for the execution of system commands. The minify.php file is vulnerable to being overwritten with malicious code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improper Access Control

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-57567

Affected Products

Pluxml Cms