CVE-2025-34104

Publication date 15 July 2025

Last updated 23 July 2025


Ubuntu priority

Description

An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.

Status

Package Ubuntu Release Status
matomo 25.04 plucky
Not affected
24.04 LTS noble Not in release
22.04 LTS jammy Not in release