PluXml CMS Authenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in PluXml CMS version 5.8.22. This vulnerability allows authenticated attackers with access to the administrator panel to inject a malicious PHP web shell into a theme file, such as home.php. The issue arises from inadequate validation of ZIP archive contents during module uploads, enabling attackers to exploit path traversal vulnerabilities and execute arbitrary code on the server.

Impact

Exploitation of this vulnerability allows authenticated administrators to execute arbitrary commands on the server, potentially leading to a full system compromise.

Reproduction

To reproduce this vulnerability, log into the PluXml CMS admin panel and navigate to the Module Management section. Upload a ZIP file containing a PHP web shell, ensuring that the file paths are crafted to exploit the application's path traversal vulnerabilities. Once the ZIP file is uploaded and extracted, access the injected PHP file through the web server to execute the web shell.

Added: Dec 22, 2025, 10:33 PM
Updated: Dec 22, 2025, 10:33 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
6.3
remediation
8.3
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.