All verified exploits

CVE-2025-52998 PHAR Deserialization Bypass

Deterministic high Chamilo Added cve-verified-cve-2025-52998

Detects case-sensitivity bypass in the Chamilo vChamilo plugin's phar:// wrapper filter. Mixed-case Phar:// input passes the str_starts_with() check, allowing PHP deserialization via file-system functions.

Is your app exploitable through CVE-2025-52998?

Scan your domain free