← Back to browse
·
API
CVE-2025-58048
Severity
CRITICAL
CVSS
10.0
EPSS
0.00401
Risk score
40.14
CISA KEV
No
PoC
No
Published
2026-06-22
Modified
2026-06-22
First seen
2026-08-07
Aliases
EUVD-2025-26130, GHSA-5PM9-R2M8-RCMJ
Products
Paymenter:Paymenter < 1.2.11
Sources
euvd
EUVD-2025-26130
Description
Paymenter vulnerable to Remote Code Execution via public file uploads
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26130
https://github.com/Paymenter/Paymenter/security/advisories/GHSA-5pm9-r2m8-rcmj
https://github.com/Paymenter/Paymenter/commit/87c3db42282ada1e3cda54b9a01f846926c0669b
https://github.com/Paymenter/Paymenter/releases/tag/v1.2.11
https://nvd.nist.gov/vuln/detail/CVE-2025-58048