CVE-2025-70364Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. NOTE: the Supplier's position is that this is "a historical and intended administrative feature of the product, accessible only to already authenticated users explicitly granted administrator privileges." However, restrictions on some PHP functions were added in 8.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-09: 3Technical Details · 2026-04-09: 304-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70364 Arbitrary PHP Code Execution in Kiamo Before 8.4 via Authenticated Admin Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70364

    Post summary

    The post presents a disclosure of CVE-2025-70364, describing an arbitrary PHP code execution vulnerability in Kiamo versions prior to 8.4 that is exploitable by authenticated administrators; no PoC, exploit, active use, patch, or debunking information is provided.

    00000129
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-70364 An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. https://www.cve.org/CVERecord?id=CVE-2025-70364 ----- Traducción: CVE-2025-70364 Se descubrió un fallo en Kiamo ante… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-70364, noting that authenticated administrators can run arbitrary PHP code on Kiamo servers, but provides no PoC, exploit tool, or patch information.

    00000344
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70364 An issue was discovered in Kiamo before 8.4 allowing authenticated administrative attackers to execute arbitrary PHP code on the server. https://www.cve.org/CVERecord?id=CVE-2025-70364

    Post summary

    A new vulnerability, CVE‑2025‑70364, allows authenticated admins of Kiamo before version 8.4 to run arbitrary PHP code on the server.

    00000227
    57.0K followersView on X

Explore more