CVE-2025-25691: Command Injection
Published Jul 30, 2025
·Updated
A PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
Affected Software
2 affected components
Prestashop PrestaShop
Prestashop PrestaShop=8.2.0
Event History
Jul 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25691?
CVE-2025-25691 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-25691?
To mitigate CVE-2025-25691, upgrade to the latest version of PrestaShop that resolves this vulnerability.
3
Who is affected by CVE-2025-25691?
CVE-2025-25691 affects users of PrestaShop v8.2.0, specifically those using the /themes/import component.
4
What type of vulnerability is CVE-2025-25691?
CVE-2025-25691 is a PHAR deserialization vulnerability that allows attackers to execute arbitrary code.
5
When was CVE-2025-25691 disclosed?
The exact disclosure date for CVE-2025-25691 is not specified, but it is important to address it immediately to prevent exploitation.