Product
ImpressCMS contains an authenticated remote code execution vulnerability (CVE-2026-73679) in the custom tag module, allowing administrators to execute arbitrary PHP code via improperly sanitized input.