Skip to content
Threat Feed

Tag

Cms

59 briefs RSS
high threat

Unauthenticated Administrative Access in Semantic MediaWiki smwtask API

The Semantic MediaWiki smwtask API module fails to enforce authorization, enabling unauthenticated remote attackers to perform sensitive information disclosure, queue administrative maintenance jobs, and manipulate stored semantic data.

exploited Semantic MediaWiki +1 api-security broken-access-control webserver web-security xss cms
1r 1t
high advisory

Grav CMS Path Traversal in MediaUploadTrait Leading to Arbitrary File Deletion

An authenticated path traversal vulnerability in Grav CMS's MediaUploadTrait allows users with media management permissions to delete arbitrary files on the server by providing crafted file paths.

Grav CMS +1 grav cms path-traversal cve-2026-72695 file-disclosure web-application
3t 1c
high advisory

Grav Privilege Escalation via Group Blueprint ACL Bypass

A missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.

Grav +2 privilege-escalation cms vulnerability web-application-vulnerability path-traversal cve-2026-74907 twig security-misconfiguration
1r 3t 1c
high advisory

Grav CMS Twig Sandbox Bypass via Configuration Exposure

CVE-2026-92917 allows an authenticated user with page-edit privileges in Grav CMS 2.0.0-rc.1 through 2.0.21 to bypass Twig sandboxing and exfiltrate the full application configuration, including API keys and credentials.

Grav +1 cms web-application security-misconfiguration information-disclosure
3t 1c updated
medium advisory

Security Bypass Vulnerability in TYPO3 Femanager Extension

A vulnerability in the TYPO3 Femanager extension (CVE-2024-42023) allows remote, unauthenticated attackers to bypass security mechanisms, potentially leading to unauthorized access within the CMS environment.

Femanager web-application cms vulnerability
1t 1c
high advisory

Authorization Bypass in Shopper Framework CollectionProducts Component

An authorization bypass vulnerability in the Shopper framework allows authenticated users with limited privileges to perform unauthorized product deletions across any collection in the database.

shopper/framework +1 web-application privilege-escalation auth-bypass web-vulnerability authorization-bypass shopper cve-2026-56828 cms
2t
high advisory

SQL Injection in Pimcore CustomReportsBundle

An authenticated SQL injection vulnerability in Pimcore's CustomReportsBundle allows users with specific permissions to execute arbitrary database commands by bypassing a weak keyword blacklist.

Pimcore +2 sql-injection web-application cms
1r 2t
high advisory

Authorization Bypass in Craft CMS assets/move-asset Endpoint

Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.

Craft CMS +3 cms web-vulnerability authorization-bypass web-application vulnerability privilege-escalation web-application-vulnerability rce +1
2r 4t 1c updated
critical advisory

Privilege Escalation in Craft CMS via Registration Flaw

Craft CMS versions prior to 5.10.11 contain a vulnerability allowing unauthenticated attackers to inherit administrator privileges by registering with the email address of a deactivated admin account when specific registration settings are active.

Craft CMS cve-2026-84795 privilege-escalation cms
1t 1c
medium advisory

Broken Access Control in TYPO3 CMS Backend and Install Tool

TYPO3 CMS versions 13.0.0 through 13.4.33 and 14.0.0 through 14.3.5 contain a broken access control vulnerability (CVE-2026-19418) that allows attackers to perform unauthorized actions by abusing ineffective referrer enforcement.

TYPO3 CMS +1 web-application cms vulnerability cve-2026-19418
2t
high threat

Missing Authorization in Kirby CMS REST API Chunked Upload Handler

Authenticated users without file upload permissions can exploit a missing authorization check in Kirby CMS to exhaust server storage via incomplete chunked file uploads, leading to denial-of-service.

exploited Kirby CMS +1 web-application denial-of-service api-security web-application-vulnerability path-traversal cms
1r 1t 1c
low advisory

Stored Cross-Site Scripting in Agentejo Cockpit CMS

Agentejo Cockpit CMS versions up to 2.6.3 contain a stored XSS vulnerability via the asset upload endpoint, allowing attackers to execute arbitrary JavaScript by uploading and accessing malicious .shtml files.

Cockpit CMS web-security xss cms
1r 2t 1c
high advisory

Pimcore Studio API Privilege Escalation via Class Definition Endpoint

An insufficient permission check in the Pimcore studio-backend-bundle allows authenticated users with standard object-editing privileges to create class definitions, leading to unauthorized schema modification and server-side file creation.

studio-backend-bundle +3 privilege-escalation cms vulnerability account-takeover cve-2026-55207 web-application-vulnerability
3r 4t 1c
high advisory

Multiple Vulnerabilities in DNN Platform

DNN is affected by multiple high-severity vulnerabilities allowing attackers to achieve remote code execution, escalate privileges, and conduct SSRF or cross-site scripting attacks.

DNN vulnerability web-application cms
3t
high advisory

Multiple Vulnerabilities in Contao CMS

Contao is affected by multiple vulnerabilities that may allow an unauthenticated or low-privileged attacker to bypass security controls, elevate privileges to administrator level, perform cross-site scripting (XSS) attacks, disclose sensitive information, and manipulate data.

Contao web-application cms vulnerability
3t
high advisory

Arbitrary File Overwrite in Grav CMS via Symlink Following

Grav CMS versions before 2.0.16 are vulnerable to arbitrary file overwrites via a symlink following flaw in the Scheduler component's lock file creation process.

Grav CMS privilege-escalation cms file-write
1t 1c
high advisory

Authorization Bypass in Grav Flex Objects Plugin

An authorization bypass vulnerability (CVE-2026-56707) in Grav Flex Objects plugin versions 1.4.0 through 1.4.7 allows authenticated users with page-edit privileges to exfiltrate sensitive data by rendering unauthorized Flex collections via shortcodes.

Flex Objects plugin web-security cms data-exposure
1t 1c
high advisory

Remote Code Execution in Grav CMS Flex Objects Plugin

Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.

Grav CMS +2 web-application-vulnerability rce ssti cms privilege-escalation web-application remote-code-execution cve-2026-75827
2r 6t 1c updated
high advisory

Improper Input Validation in Winter CMS Backend Postback

Authenticated backend users can exploit an input validation vulnerability in the Winter CMS form postback mechanism to execute restricted controller methods, leading to unauthorized administrative actions.

wn-backend-module web-application privilege-escalation cms
1t
high advisory

Statamic CMS Account Takeover via Unverified OAuth Email Matching

An unauthenticated attacker can achieve account takeover by leveraging unverified OAuth email matching in Statamic CMS, allowing unauthorized authentication as existing users including administrators.

Statamic CMS oauth account-takeover cms authentication-bypass
1t
critical advisory

Arbitrary Password Reset Vulnerability in Craft CMS

An insecure mass-assignment vulnerability in the Craft CMS user element save action allows authenticated users with specific permissions to modify passwords without requiring the current password or elevated verification.

Craft CMS +1 privilege-escalation cms web-application authentication-bypass cve-2024-45398
5t updated
critical advisory

Unauthenticated Remote Code Execution in MaxSite CMS via Config Injection

MaxSite CMS is vulnerable to remote code execution due to improper input sanitization of the db_dbprefix parameter, allowing unauthenticated attackers to inject persistent PHP code into the database configuration file.

PoC MaxSite CMS +2 web-application cms vulnerability
1r 1t 3c 1i updated
high advisory

Authenticated Remote Code Execution in Camaleon CMS

Camaleon CMS versions 2.1.1 through 2.9.1 are vulnerable to authenticated remote code execution where an attacker with `custom_fields manage` permission can execute arbitrary Ruby code by injecting a malicious expression into the `select_eval` custom field type's options command parameter, which is then evaluated via `instance_eval` within an ERB view when a post edit page is rendered, leading to server-side code execution with web server process privileges.

Camaleon CMS remote-code-execution cms vulnerability
1t 1c
high advisory

Microweber CMS Server-Side Template Injection Leads to RCE (CVE-2026-65693)

An authenticated administrator in Microweber CMS through version 2.0.20 is vulnerable to server-side template injection due to an unsandboxed Twig environment, allowing for arbitrary OS command execution by injecting malicious Twig expressions into mail templates, which are executed automatically upon mail dispatch and can compromise the underlying server.

Microweber CMS through 2.0.20 server-side-template-injection rce cms web-application microweber
2t 1c
high threat

VikBooking Hotel Booking Engine & PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)

The VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.

VikBooking Hotel Booking Engine & PMS plugin for WordPress wordpress xss web-vulnerability stored-xss cms
1r 2t 1c
high advisory

Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)

An unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.

PoC Microweber CMS +1 web-vulnerability path-traversal cms webserver
1r 2t 1c 2i updated
high advisory

Grav CMS Remote Code Execution Vulnerability (CVE-2026-65608)

An authenticated remote code execution vulnerability (CVE-2026-65608) in Grav CMS versions 1.7.0 through 2.0.8 allows attackers with Flex directory create/update permissions to execute arbitrary shell commands due to improper input validation in `FlexDirectory::dynamicDataField()`.

Grav +1 RCE CMS PHP web-exploitation
2r 1t 1c updated
high threat

Critical Access Bypass Vulnerability in Drupal Internationalization Single Sign-On Module

A critical access bypass vulnerability (SA-CONTRIB-2026-081) exists in the Internationalization Single Sign-On module for Drupal, affecting versions prior to 1.8.0, allowing an attacker to bypass authentication mechanisms and potentially gain unauthorized access or elevate privileges within the application.

exploited Internationalization Single Sign-On drupal cms vulnerability access-bypass web-application
1t
critical advisory

Grav Login Plugin Privilege Escalation (CVE-2026-65603)

A critical privilege escalation vulnerability, CVE-2026-65603, exists in the Grav Login plugin (grav-plugin-login) versions up to and including 3.8.11, allowing an authenticated low-privilege user to exploit a flaw in the `processUserProfile()` handler to bypass privilege stripping and escalate to super-admin, enabling admin panel access, remote code execution, and Twig evaluation.

Grav Login plugin privilege-escalation web-vulnerability grav cms
2t 1c
critical advisory

Grav API Plugin Authorization Bypass Leads to Account Takeover (CVE-2026-65007)

The Grav api plugin (grav-plugin-api) versions prior to 1.0.8 contain an authorization bypass vulnerability where the plugin intercepts API key generation and revocation tasks before proper ACL checks, allowing any user with the baseline admin.login permission to generate or revoke API keys for any account, enabling impersonation, privilege escalation, and potential account takeover.

grav-plugin-api authorization-bypass privilege-escalation account-takeover cms
3t 1c
high advisory

Arbitrary File Upload Vulnerability in ProfilePress WordPress Plugin (CVE-2026-13352)

An arbitrary file upload vulnerability, CVE-2026-13352, affects the ProfilePress plugin for WordPress up to version 4.16.18, allowing authenticated attackers with author-level privileges or higher to upload executable files, which can lead to remote code execution.

ProfilePress plugin for WordPress wordpress vulnerability rce file-upload cms
3t 1c
high advisory

Grav Form Plugin Arbitrary File Write Vulnerability (CVE-2026-61873)

Grav before version 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, allowing attackers to bypass path traversal validation via Twig template processing and write PHP webshells for remote code execution.

Grav arbitrary-file-write rce web-vulnerability cms path-traversal
1r 3t 1c
high advisory

Grav Flex Objects Plugin Stored Template Injection Leading to RCE

A stored server-side template injection vulnerability, identified as CVE-2026-58655, exists in the Grav Flex Objects plugin before version 1.4.0, allowing an attacker to achieve arbitrary Twig execution and remote command execution by injecting malicious code into user-controlled title frontmatter that bypasses sanitization.

Grav Flex Objects plugin < 1.4.0 template-injection rce web-vulnerability cms grav php
1r 1t 1c
high advisory

Cockpit CMS Missing Authorization Vulnerability in Bucket File Storage API (CVE-2026-57855)

A missing authorization vulnerability, CVE-2026-57855, in the Cockpit CMS Bucket file storage API allows any authenticated user, regardless of their assigned role, to perform all file operations on any named bucket, including those designated for administrative use, potentially leading to privilege escalation, data manipulation, or data destruction.

Cockpit CMS < 2.14.0 vulnerability web-application cms authorization-bypass privilege-escalation
4t 1c
high advisory

NukeViet Multiple Anti-XSS Filter Bypasses Leading to Stored XSS

Two filter-bypass techniques in NukeViet\Core\Request allow a low-privileged user with news-posting permission to store and execute arbitrary JavaScript in the browsers of any visitor to an affected page, leading to session cookie theft, credential harvesting, defacement, and further privilege escalation via CVE-2026-54064.

NukeViet xss web-vulnerability cms cross-site-scripting filter-bypass
2t
high advisory

NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function

An authenticated administrator in NukeViet is vulnerable to a path traversal flaw (CVE-2026-54065) in the Edit Comment admin function, allowing an attacker to inject a crafted `attach` parameter which, upon comment deletion, leads to arbitrary file deletion within the application root, causing a full application outage and exposing the install wizard.

NukeViet path-traversal arbitrary-file-deletion web-vulnerability cms
1r 2t
high advisory

NukeViet CMS Stored Cross-Site Scripting Vulnerability

A stored cross-site scripting (XSS) vulnerability, CVE-2026-49259, exists in NukeViet CMS versions 4.x through 4.5.08, including the 'composer/nukeviet/nukeviet' package prior to version 4.5.09, which allows a low-privileged authenticated user to inject JavaScript into their profile's display name fields that executes in the browser of any visitor, including administrators, who clicks the 'Reply' link on a comment posted by the attacker, leading to arbitrary JavaScript execution, administrative session hijacking, credential phishing, and data exfiltration.

NukeViet CMS < 4.5.09 +1 xss web-vulnerability cms nukeviet stored-xss
1r 2t
low advisory

Contao Information Disclosure Vulnerability

An authenticated remote attacker can exploit a vulnerability in Contao to disclose sensitive information, gaining unauthorized access to data within the system.

Contao information-disclosure cms vulnerability web-application
1t
high advisory

WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection

The Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.

Booking Package plugin <= 1.7.20 wordpress sqli web-vulnerability cms
1t 1c
high advisory

Craft CMS RCE via Missing cleanseConfig in FieldsController

An authenticated administrator in Craft CMS (versions 5.5.0 to 5.9.13) is vulnerable to Remote Code Execution (RCE) via a missing input sanitization vulnerability in the `actionRenderCardPreview()` method of `FieldsController`, allowing Yii2 event handler injection through specially crafted `fieldLayoutConfig` POST parameters, which enables arbitrary PHP code execution and sensitive information disclosure.

Craft CMS rce web-application cms craft-cms php
1r 1t
medium advisory

Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification

Multiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.

Joomla cms vulnerability xss web-vulnerability data-integrity
1t
high advisory

Multiple Vulnerabilities Discovered in Joomla! CMS

Multiple vulnerabilities, including several Cross-Site Scripting (XSS) flaws and incorrect access control issues, have been discovered in Joomla! versions 6.x prior to 6.1.2 and 5.x prior to 5.4.7, which could allow an attacker to bypass security policies, compromise data confidentiality and integrity, and perform remote indirect code injection.

Joomla! +1 web-vulnerability xss access-control cms joomla
4t 5c 24i
high advisory

CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability

A stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.

VikBooking Hotel Booking Engine & PMS plugin < 1.8.9 wordpress plugin xss web-vulnerability cms
1r 5t 1c
high advisory

CVE-2026-23698: Vtiger CRM Authenticated Remote Code Execution

Vtiger CRM versions up to and including 8.4.0 are vulnerable to authenticated remote code execution (CVE-2026-23698), allowing administrator-level attackers to upload malicious PHP web shells via the ModuleManager import function, bypassing authentication and leading to persistent system compromise.

Vtiger CRM cve rce webserver web-application cms
1r 2t
high advisory

Multiple Vulnerabilities in SPIP CMS Lead to Data Confidentiality Loss

Multiple vulnerabilities, including SQL injection and indirect remote code injection (XSS), were discovered in SPIP Content Management System versions prior to 4.4.16, allowing an attacker to compromise data confidentiality and execute malicious code in user browsers.

SPIP vulnerability web-application sqli xss cms
3t
high advisory

Craft CMS Mass Assignment Vulnerability Allows Element Overwrites (CVE-2026-50281)

A high-severity mass assignment vulnerability (CVE-2026-50281) in Craft CMS versions prior to 5.9.21 allows a low-privileged authenticated attacker to overwrite arbitrary existing element data, such as entries or user profiles, by manipulating the `newAttributes` parameter during a bulk duplication action.

Craft CMS web-application vulnerability mass-assignment cve cms
1t 1c
high advisory

Craft CMS Vulnerable to Unauthorized Folder Deletion (CVE-2026-50282)

A high-severity vulnerability (CVE-2026-50282) in Craft CMS allows an authenticated user to delete destination folders and their contents without explicit delete permissions during a forced folder move operation, enabling asset loss, breaking existing asset references, and causing operational disruption.

Craft CMS +1 authorization-bypass cms craft-cms webserver cve
1t 1c
high advisory

CVE-2026-58593: NodeBB ActivityPub Forgery Vulnerability

A critical vulnerability (CVE-2026-58593) in NodeBB's ActivityPub implementation allows a remote attacker to forge posts and direct messages attributed to arbitrary local users, including administrators, by manipulating the 'attributedTo' field in inbound ActivityPub objects.

PoC NodeBB +1 activitypub federation vulnerability web-application cms forgery
1t 1c updated
high advisory

AlchemyCMS: Unauthenticated Nested Page API Leaks Restricted & Unpublished Content

An unauthenticated API endpoint, `GET /api/pages/nested`, in Alchemy CMS versions up to 8.2.5 (including all 8.x versions prior to a fix and all 7.x versions up to 7.4.14), fails to enforce authorization and scoping checks, allowing any anonymous user to retrieve the complete page tree, encompassing restricted and unpublished pages, and, with `?elements=true`, the full content of these sensitive pages, completely bypassing intended access controls and leading to unauthorized information disclosure.

Alchemy CMS +3 web-vulnerability information-disclosure cms rails ruby
2r
high advisory

Kirby: Self cross-site scripting (self-XSS) in the writer field (CVE-2026-49276)

Kirby CMS versions prior to 4.9.4 and between 5.0.0-alpha.1 and 5.4.3 are vulnerable to a self-cross-site scripting (self-XSS) flaw, CVE-2026-49276, in the writer field, allowing an attacker to inject malicious JavaScript as the target of a link or email link which, if clicked by an authenticated user before saving, will execute in their browser context, potentially making API requests with their permissions, while Panel plugins using the `<k-writer>` component may be vulnerable to stored XSS if they don't sanitize HTML.

composer/getkirby/cms <= 4.9.3 +1 xss self-xss web-vulnerability kirby cms
2r 3t
high threat

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in Dom::sanitize()

A high-severity cross-site scripting (XSS) vulnerability, tracked as CVE-2026-54002, exists in Kirby CMS versions prior to 4.9.4 and between 5.0.0-alpha.1 and 5.4.3, allowing authenticated Panel users to inject malicious markup into `writer` or `list` fields or via `Sane` API-dependent custom code, leading to stored XSS and potential privilege escalation.

Kirby CMS +1 Authenticated Panel User xss web-application cms kirby-cms
2r 2t
high advisory

Kirby CMS Missing Authorization Vulnerability in /api/site/find (CVE-2026-54005)

An authenticated user can exploit CVE-2026-54005, a high-severity missing authorization vulnerability in Kirby CMS versions <= 4.9.3 and from 5.0.0-alpha.1 to <= 5.4.3, via the `/api/site/find` REST API route to bypass `pages.access` permissions and retrieve sensitive content and metadata from unauthorized pages.

composer/getkirby/cms +1 cms vulnerability kirby information-disclosure api webserver
2r 3t
critical advisory

Critical Kirby CMS Vulnerability Allows Remote Admin Account Creation via Reverse Proxy Headers (CVE-2026-54003)

A critical external initialization vulnerability (CVE-2026-54003) in Kirby CMS allows unauthenticated attackers to create an initial admin account on sites running behind a reverse proxy, specifically when the proxy utilizes `Forwarded: for=...`, `X-Client-IP`, or `X-Real-IP` headers, bypassing Kirby's `isLocal` check and enabling remote Panel installation with full administrative access.

Kirby CMS +1 web-vulnerability cms initial-access privilege-escalation kirby
2r 2t
critical advisory

Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities

Progress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.

PoC Sitefinity CMS +9 vulnerability web-application cms load-balancer patch-management cve
3r 1t 5c 4i updated
high advisory

Kirby CMS Missing Authorization Vulnerability

A missing authorization vulnerability in Kirby CMS allows authenticated users to bypass intended access restrictions on pages and files, potentially leading to unauthorized information disclosure and content modification; patched in versions 4.9.0 and 5.4.0.

cms +3 authorization web-application
2r 2t
high advisory

Sharp CMS Path Traversal Vulnerability (CVE-2026-33686)

A path traversal vulnerability exists in Sharp CMS versions prior to 9.20.0 due to improper sanitization of file extensions, potentially allowing attackers to bypass security restrictions and access sensitive files.

path-traversal cms laravel web-application
2r 1t
medium advisory

CI4MS Improper Sanitization of User Input Leading to XSS

CI4MS versions prior to 0.31.2.0 are vulnerable to stored cross-site scripting due to improper sanitization of user-controlled input within the System Settings – Company Information, allowing attackers to inject arbitrary JavaScript into public-facing pages.

CI4MS xss codeigniter cms
2r 1t 1c
critical advisory

Grav Form Plugin Anonymous Page Content Overwrite Vulnerability

Grav Form plugin versions before 9.1.0 allow unauthenticated users to overwrite page content by uploading a malicious markdown file, leading to potential privilege escalation by crafting a new super-admin user.

grav-plugin-form grav cms file-upload privilege-escalation content-overwrite
2r 2t
high advisory

FuelCMS Vulnerability Report

A vulnerability in FuelCMS has been reported, details available at pentesttools.com/blog/throwing-a-spark-in-fuelcms, potentially allowing attackers to compromise vulnerable systems.

FuelCMS vulnerability cms
2r 2t 1i