CRITICAL
wisdom
CVE published 2026-04-05
CVE-2019-25687
CVE-2019-25687 is a remote code execution vulnerability in Pegasus CMS 1.0, specifically in the extra_fields.php plugin. This vulnerability allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can achieve code execution by sending POST requests to the submit.php endpoint with malicious PHP code in the action parameter, potentially obtaining an i [truncated]