Livewire Filemanager Vulnerability Exposes Web Applications to RCE Attacks
ID: 3a9e6929-2fe6-553c-acaf-f12806e3b27d
STIX ID: report--3a9e6929-2fe6-553c-acaf-f12806e3b27d
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated remote code execution vulnerability (CVE-2025-14894 / VU#650657) in Livewire Filemanager allows attackers to upload and execute PHP webshells via the Laravel storage link; CERT/CC advises immediate mitigations including disabling public storage links, enforcing strict upload allowlists and MIME validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
