CVEPublished 2025-08-061 article on news7 live referencesNVD data

CVE-2025-50286

Vulnerability data via CVEDB (Shodan)

CVSS v3.1
8.1
HIGH
EPSS percentile
94
Exploit Prediction Scoring System · top 6% of all CVEs
Description

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.

Timeline
Published 2025-08-06

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (1)