
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-51511 is an unrestricted file upload vulnerability (CWE-434) in Cadmium CMS v.0.4.9, a PHP-based content management system. The flaw exists in the /admin/content/filemanager/uploads endpoint and allows attackers to upload arbitrary files — including PHP web shells — without proper validation or authentication controls. It was disclosed on December 23, 2025, and affects only version 0.4.9 of the Composer package cadmium-org/cadmium-cms. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) as assessed by CISA-ADP (Github Advisory, GitHub Issue).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the file manager endpoint /admin/content/filemanager/uploads fails to validate uploaded file types or enforce authentication, allowing any network-accessible attacker to upload executable PHP files. According to the public issue report, an attacker can upload an image file containing malicious PHP code and then rename it with a .php extension, making it directly accessible and executable via the web server at a path such as http://target.com/uploads/phpinfo.php. No complex prerequisites, user interaction, or elevated privileges are required for exploitation (GitHub Issue, Github Advisory).
Successful exploitation enables full remote code execution (RCE) on the affected server, giving an attacker the ability to execute arbitrary commands under the web server's process context. This results in complete compromise of confidentiality (access to sensitive data, credentials, and configuration files), integrity (modification or deletion of system and application files), and availability (service disruption or ransomware deployment). The network-accessible nature of the vulnerability with no authentication requirement means any internet-facing Cadmium CMS v.0.4.9 instance is immediately at risk, and a foothold could be leveraged for lateral movement within the hosting environment (Github Advisory, GitHub Issue).
A proof-of-concept (PoC) exploit has been publicly documented in the GitHub issue tracker for the Cadmium CMS project, demonstrating the upload and execution of a PHP web shell (GitHub Issue). There is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time (Github Advisory). The EPSS score is approximately 0.056% (0.2% per GitHub Advisory), placing it in the 42nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
composer.json.http://target.com/admin/content/filemanager/uploads — no authentication is required to interact with this endpoint.<?php system($_GET['cmd']); ?>) embedded within or disguised as an image file (e.g., shell.jpg)./admin/content/filemanager/uploads endpoint via an HTTP POST request..php extension to change the file name to something like shell.php.http://target.com/uploads/shell.php?cmd=id to achieve remote code execution on the server (GitHub Issue)./admin/content/filemanager/uploads from external or unknown IP addresses; HTTP GET requests to /uploads/*.php files, particularly with query parameters like cmd, exec, or c..php files in the /uploads/ directory (e.g., shell.php, phpinfo.php, cmd.php); files with PHP content disguised with image extensions (e.g., .jpg, .png) in the uploads directory./admin/content/filemanager/uploads followed by GET requests to /uploads/<filename>.php; PHP error logs showing execution of system commands or unusual function calls.bash, curl, wget, python, nc) indicating command execution via the web shell (GitHub Issue).The GitHub Advisory Database notes that no patched version has been formally released for the cadmium-org/cadmium-cms Composer package (all versions ≤ 0.4.9 are listed as affected), and the project appears to be in an unmaintained state (Github Advisory). Organizations should immediately restrict network-level access to the /admin/content/filemanager/uploads endpoint using a Web Application Firewall (WAF) or firewall rules. Additional mitigations include: disabling PHP execution in the /uploads/ directory via server configuration (e.g., Apache .htaccess or Nginx location blocks), monitoring the uploads directory for unexpected .php files, and considering migration to an actively maintained CMS if a vendor patch is not forthcoming.
The vulnerability was covered by The Hacker Wire, which published an article titled "Critical Arbitrary File Upload in Cadmium CMS 0.4.9 Exposes Systems to RCE" (The Hacker Wire). Social media posts on Bluesky and Mastodon (infosec.exchange) also highlighted the disclosure shortly after publication. Community reaction has been limited given the niche nature of the affected software, but the critical CVSS score and unauthenticated RCE potential drew attention from vulnerability tracking services including VulDB, Vulners, and CVEFeed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."