A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the argument content leads to code injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 05 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Kodicms-kohana
Kodicms-kohana kodicms
CPEs cpe:2.3:a:kodicms-kohana:kodicms:*:*:*:*:*:*:*:*
Vendors & Products Kodicms-kohana
Kodicms-kohana kodicms

Mon, 05 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Kohana
Kohana kodicms
Vendors & Products Kohana
Kohana kodicms

Wed, 31 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the argument content leads to code injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Kohana KodiCMS Layout API Endpoint file.php save code injection
Weaknesses CWE-74
CWE-94
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-12-31T18:32:05.051Z

Updated: 2026-01-05T14:40:23.007Z

Reserved: 2025-12-31T09:16:51.462Z

Link: CVE-2025-15393

cve-icon Vulnrichment

Updated: 2026-01-05T14:40:06.980Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-31T19:15:43.380

Modified: 2026-01-05T18:33:02.763

Link: CVE-2025-15393

cve-icon Redhat

No data.