CVE-2025-50286
CVE-2025-50286
Vexday Risk Score
56Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.1EPSS 8.7%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Lifecycle
05 Aug 2025Public PoC
06 Aug 2025Published on NVD
07 Aug 2025Metasploit module available
Recommendation: Plan a near-term fix — a public PoC already exists.
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/binneko/CVE-2025-50286★ 2githubgithub.com/x1o3/CVE-2025-50286★ 0exploitdbwww.exploit-db.com/exploits/52402unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →