CVE-2022-25018 describes a critical arbitrary code execution vulnerability in Pluxml v5.8.7, allowing authenticated attackers to insert malicious PHP code into static pages. With a CVSS score of 8.8 (High), this low-complexity network attack grants full confidentiality, integrity, and availability impact. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the high FAUCET Risk Score of 81/100 indicates significant potential danger. Organizations using affected Pluxml versions should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.8.7CPE matchmatch criteria | cpe:2.3:a:pluxml:pluxml:5.8.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.