CVE-2025-34104: CWE-434 Unrestricted Upload of File with Dangerous Type in Piwik (now Matomo) Web Analytics Platform
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-34104) involves an unrestricted file upload flaw (CWE-434) combined with insufficient authentication controls (CWE-306) in Piwik/Matomo versions before 3.0.3. An attacker with Superuser privileges can upload a crafted ZIP archive as a plugin and activate it, leading to remote code execution on the underlying system. The issue is addressed by disabling plugin uploads by default starting in version 3.0.3, requiring explicit configuration to enable this feature.
Potential Impact
Successful exploitation allows an authenticated Superuser to execute arbitrary PHP code on the server hosting the Matomo platform, potentially leading to full system compromise. This elevates the risk to critical severity given the high privileges required and the direct code execution impact.
Mitigation Recommendations
Upgrade to Matomo version 3.0.3 or later, where plugin upload functionality is disabled by default unless explicitly enabled in the configuration file. If upgrading is not immediately possible, ensure that plugin uploads are disabled in the configuration to prevent exploitation. No official patch link is provided, but the vendor's configuration change mitigates the vulnerability.
CVE-2025-34104: CWE-434 Unrestricted Upload of File with Dangerous Type in Piwik (now Matomo) Web Analytics Platform
Description
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
CVSS v4.0
Score 9.4critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-34104) involves an unrestricted file upload flaw (CWE-434) combined with insufficient authentication controls (CWE-306) in Piwik/Matomo versions before 3.0.3. An attacker with Superuser privileges can upload a crafted ZIP archive as a plugin and activate it, leading to remote code execution on the underlying system. The issue is addressed by disabling plugin uploads by default starting in version 3.0.3, requiring explicit configuration to enable this feature.
Potential Impact
Successful exploitation allows an authenticated Superuser to execute arbitrary PHP code on the server hosting the Matomo platform, potentially leading to full system compromise. This elevates the risk to critical severity given the high privileges required and the direct code execution impact.
Mitigation Recommendations
Upgrade to Matomo version 3.0.3 or later, where plugin upload functionality is disabled by default unless explicitly enabled in the configuration file. If upgrading is not immediately possible, ensure that plugin uploads are disabled in the configuration to prevent exploitation. No official patch link is provided, but the vendor's configuration change mitigates the vulnerability.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.556Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687654a5a83201eaaccea4f8
Added to database: 07/15/2025, 13:16:21 UTC
Last enriched: 07/15/2026, 09:50:57 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 189
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.