CVE detail
CVE-2019-25729
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.vulncheck.com/advisories/pdf-signer-server-side-template-injection-rce-via-csrf-cookiewww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comJun 4, 2026, 2:16 PM - https://www.exploit-db.com/exploits/46276www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comJun 4, 2026, 2:16 PM - https://codecanyon.net/user/simcy_creativecodecanyon.net
No excerpt available.
referencecodecanyon.netJun 4, 2026, 2:16 PM - https://codecanyon.net/item/signer-create-digital-signatures-and-sign-pdf-documents-online/20737707codecanyon.net
No excerpt available.
referencecodecanyon.netJun 4, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-64791CVSS N/A · Unrated
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF a…
- CVE-2026-63684CVSS N/A · Unrated
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks co…
- CVE-2026-63280CVSS N/A · Unrated
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
- CVE-2026-63265CVSS N/A · Unrated
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authent…
- CVE-2026-62563CVSS 5.4 · Medium
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily e…
- CVE-2026-62487CVSS 6.1 · Medium
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea…