Skip to content
Threat Feed

Product

CMS

4 briefs RSS
high advisory

Authorization Bypass in light0011 CMS

An authorization bypass vulnerability in the light0011 CMS AuthController component allows remote, unauthenticated attackers to access restricted administrative functions.

cms web-application sql-injection cve-2026-85379
1t 1c
critical advisory

SQL Injection Vulnerability in Loca Software CMS

An unauthenticated SQL injection vulnerability (CVE-2026-5134) in Loca Software CMS allows remote attackers to execute arbitrary database commands.

CMS web-vulnerability sqli cve-2026-5134
1r 1t 1c
critical advisory

CVE-2021-47964: Schlix CMS Remote Code Execution via Malicious Extension Upload

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability, tracked as CVE-2021-47964, allowing authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager and triggering execution by accessing the 'About' tab.

CMS CVE-2021-47964 rce schlix cms php
2r 1t 1c
high advisory

Kirby CMS Server-Side Template Injection via Double Template Resolution

A server-side template injection (SSTI) vulnerability exists in Kirby CMS within the option rendering feature due to double template resolution in option fields (checkboxes, color, multiselect, select, radio, tags, or toggles) when using options from a query or API with untrusted values, potentially allowing attackers to inject malicious queries.

cms ssti kirby template-injection
2r 1t