Record summary

CVE-2025-34104 has a selected CVSS score of 9.4 (critical); EIP currently links 1 catalogued exploit.

Description

An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 3.0.3affected

Proofs of concept

1

Catalogued exploits

MetasploitPiwik Superuser Plugin UploadMetasploit exploitby FireFartNot analyzed1 file

Ruby

Metasploit

PoC details

References

6