VendorsMagdesignpocketvj_control_panelall versions
Vulnerabilities

Magdesign Pocketvj Control Panel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-63334
PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands with root privileges on the underlying system.
Published 2025-11-05 · Analyzed
9.8EPSS 0.011
CVE-2025-45326
An issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.
Published 2025-09-23 · Analyzed
6.5EPSS 0.003