🔐 CVE Alert

CVE-2023-53889

UNKNOWN 0.0

Perch CMS 3.2 Remote Code Execution via Unrestricted File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attackers can upload a malicious .phar file with embedded system command execution capabilities to execute arbitrary commands on the server.

CWE CWE-434
Vendor perch
Product perch
Published Dec 15, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for perch perch

Be the first to know when new unknown vulnerabilities affecting perch perch are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Perch / Perch
3.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/51620 grabaperch.com: https://grabaperch.com/ vulncheck.com: https://www.vulncheck.com/advisories/perch-cms-remote-code-execution-via-unrestricted-file-upload

Credits

Mirabbas Ağalarov