CVE-2025-58449
Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions can create a custom option on a listing with a file input field. By allowing file uploads with a `.php` extension, the user can use the filed to upload malicious PHP files, gaining remote code execution. Version 25.9.0 fixes the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.31%
- CWE
- CWE-646
- Published
- 2025-09-08
- Last modified
- 2026-03-13
Affected products
- MahoCommerce maho
Weakness type
Related vulnerabilities
- CVE-2026-45315 — Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
- CVE-2026-20172 — Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
- CVE-2025-30662 — Zoom Workplace VDI Plugin macOS Universal Installer - Symlink Following
- CVE-2025-41720 — Sauter: Arbitrary File Upload
- CVE-2025-1889 — picklescan - Security scanning bypass via non-standard file extensions
- CVE-2024-52052 — Stream Target Remote Code Execution in Wowza Streaming Engine
- CVE-2024-38432 — Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File
- CVE-2023-45599 — A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the...