PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105329 TallCMS CVE debrief

A code injection vulnerability was determined in TallCMS up to 4.8.0, affecting the PluginManager component's ThemeManager.php file. This issue allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. Defenders should assess exposure and apply the patch to prevent code injection attacks. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record was published on 2026-10-05T15:15:16.262Z.

Vendor
TallCMS
Product
TallCMS
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-07
Advisory published
2026-10-05
Advisory updated
2026-10-07

Who should care

Defenders responsible for systems using TallCMS, particularly those using version 4.8.0 or earlier, should assess exposure and apply the patch to prevent code injection attacks. Roles responsible for system updates and vulnerability management should prioritize this patch. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record was published on 2026-10-05T15:15:16.262Z. Defenders should review and update TallCMS to a version if

Why it matters

Defenders should care about CVE-2026-105329 because it allows remote code injection in TallCMS up to version 4.8.0, with a publicly disclosed exploit. Applying the patch is crucial to prevent potential attacks. Roles responsible for system updates and vulnerability management should prioritize this patch.

  • Remote code injection is possible, allowing attackers to execute arbitrary code
  • Publicly disclosed exploit exists, increasing the risk of exploitation
  • Patch is available, requiring application to prevent exploitation
  • Verification of system exposure and patch application is necessary

Technical summary

The vulnerability affects the ThemeManager.php file in the PluginManager component of TallCMS up to version 4.8.0. It allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. The CVSS score is 5.3, and the severity is MEDIUM. Defenders should assess exposure and apply the patch to prevent code injection attacks. The vulnerability has been publicly disclosed and may be utilized. The official CVE record and NVD entry list TallCMS as the affected package name and version (up to 4.8.0).

Defensive priority

Apply patch to resolve code injection vulnerability in TallCMS PluginManager

Recommended defensive actions

  • Apply the patch fdc18f4c6a36134f8986ca1d7e4e97092e3deb93 to resolve the code injection vulnerability
  • Review and update TallCMS to a version beyond 4.8.0 if available
  • Monitor systems using TallCMS for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The official CVE record and NVD entry list TallCMS as the affected package name and version (up to 4.8.0). The CVE‑Program JSON source item also contains the package name 'TallCMS'. The vulnerability affects the ThemeManager.php file in the PluginManager component of TallCMS up to version 4.8.0. It allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. The CVSS score is 5.3, and the severity is MEDIUM.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105329 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105329

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105329 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105329

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • TallCMS PluginManager ThemeManager.php code injection

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105329.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413543

    Supplemental source - vdb-entry

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/vuln/413543/cti

    Supplemental source - signature, permissions-required

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/cve/CVE-2026-105329

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://vuldb.com/submit/979800

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/tallcms/tallcms/issues/122

    Supplemental source - exploit, issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/tallcms/tallcms/pull/124

    Supplemental source - issue-tracking, patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/beegoodit/tallcms/commit/fdc18f4c6a36134f8986ca1d7e4e97092e3deb93

    Supplemental source - patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.