PatchSiren

wisdom CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL wisdom CVE published 2026-04-05

CVE-2019-25687

CVE-2019-25687 is a remote code execution vulnerability in Pegasus CMS 1.0, specifically in the extra_fields.php plugin. This vulnerability allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can achieve code execution by sending POST requests to the submit.php endpoint with malicious PHP code in the action parameter, potentially obtaining an i [truncated]