CVE-2025-34104 – Piwik (Matomo) Remote Code Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2025-34104 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 15, 2025

    Action Type Old Value New Value
    Added Description An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-306
    Added CWE CWE-434
    Added Reference https://firefart.at/post/turning_piwik_superuser_creds_into_rce/
    Added Reference https://matomo.org/changelog/piwik-3-0-3/
    Added Reference https://matomo.org/faq/plugins/faq_21/
    Added Reference https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/piwik_superuser_plugin_upload.rb
    Added Reference https://www.vulncheck.com/advisories/piwik-authenticated-rce-via-custom-plugin-upload
Share the Post:

Related Posts