Pagekit CMS is vulnerable to OS Command Injection via Storage component
Critical severity
GitHub Reviewed
Published
Dec 17, 2025
to the GitHub Advisory Database
•
Updated Dec 18, 2025
Description
Published by the National Vulnerability Database
Dec 17, 2025
Published to the GitHub Advisory Database
Dec 17, 2025
Reviewed
Dec 18, 2025
Last updated
Dec 18, 2025
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.
The project is archived as of December 1, 2023.
References