← Back to browse · API

CVE-2025-67164

Severity
CRITICAL
CVSS
9.9
EPSS
0.00523
Risk score
39.78
CISA KEV
No
PoC
No
Published
2025-12-17
Modified
2025-12-17
First seen
2026-08-07
Aliases
EUVD-2025-203907, GHSA-M4F2-XPFQ-H97V
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-203907

Description

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

References