Vulnerability Description
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/JamesHeinrich/phpThumb/commit/cdcbc206ae601b15fd17e7aadf59df5
- https://github.com/JamesHeinrich/phpThumb/releases
- https://safety-online.pl/cve-2025-52994/
FAQ
What is CVE-2025-52994?
CVE-2025-52994 is a vulnerability with a CVSS score of 4.9 (MEDIUM). gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.
How severe is CVE-2025-52994?
CVE-2025-52994 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52994?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.