Articles tagged CMS
-
VulnerabilitySPIP Code Injection (CVE-2026-77806)
CVE-2026-77806 is a CVSS 9.8 code injection flaw in the SPIP CMS allowing unauthenticated RCE, with NVD itself noting exploitation in the wild.
-
VulnerabilityZ-BlogPHP Access Control Flaw (CVE-2026-8747)
CVE-2026-8747 is an improper authorization vulnerability in the comment-approval handler of Z-BlogPHP 1.7.4.3430, exploitable remotely with a public exploit.
-
VulnerabilityKirby CMS Information Disclosure (CVE-2026-69127)
CVE-2026-69127 lets Kirby CMS's REST API leak the full server filesystem path in unsanitized error messages, useful for guessing the content.salt secret, fixed in Kirby 4.9.5 and 5.5.2.
-
VulnerabilityRedaxo CMS MyEvents Addon 2.2.1 SQL Injection (CVE-2018-25319)
CVE-2018-25319 is a CVSS 7.1 high-severity SQL injection in the MyEvents addon for Redaxo CMS, only recently scored by NVD despite the original disclosure dating to 2018.