Product
Authorization Bypass in light0011 CMS
1 TTP 1 CVEAn authorization bypass vulnerability in the light0011 CMS AuthController component allows remote, unauthenticated attackers to access restricted administrative functions.
SQL Injection Vulnerability in Loca Software CMS
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-5134) in Loca Software CMS allows remote attackers to execute arbitrary database commands.
CVE-2021-47964: Schlix CMS Remote Code Execution via Malicious Extension Upload
2 rules 1 TTP 1 CVESchlix CMS 2.2.6-6 contains a remote code execution vulnerability, tracked as CVE-2021-47964, allowing authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager and triggering execution by accessing the 'About' tab.
Kirby CMS Server-Side Template Injection via Double Template Resolution
2 rules 1 TTPA server-side template injection (SSTI) vulnerability exists in Kirby CMS within the option rendering feature due to double template resolution in option fields (checkboxes, color, multiselect, select, radio, tags, or toggles) when using options from a query or API with untrusted values, potentially allowing attackers to inject malicious queries.