PatchSiren cyber security CVE debrief
CVE-2026-105329 TallCMS CVE debrief
A code injection vulnerability was determined in TallCMS up to 4.8.0, affecting the PluginManager component's ThemeManager.php file. This issue allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. Defenders should assess exposure and apply the patch to prevent code injection attacks. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record was published on 2026-10-05T15:15:16.262Z.
- Vendor
- TallCMS
- Product
- TallCMS
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for systems using TallCMS, particularly those using version 4.8.0 or earlier, should assess exposure and apply the patch to prevent code injection attacks. Roles responsible for system updates and vulnerability management should prioritize this patch. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The CVE record was published on 2026-10-05T15:15:16.262Z. Defenders should review and update TallCMS to a version if
Why it matters
Defenders should care about CVE-2026-105329 because it allows remote code injection in TallCMS up to version 4.8.0, with a publicly disclosed exploit. Applying the patch is crucial to prevent potential attacks. Roles responsible for system updates and vulnerability management should prioritize this patch.
- Remote code injection is possible, allowing attackers to execute arbitrary code
- Publicly disclosed exploit exists, increasing the risk of exploitation
- Patch is available, requiring application to prevent exploitation
- Verification of system exposure and patch application is necessary
Technical summary
The vulnerability affects the ThemeManager.php file in the PluginManager component of TallCMS up to version 4.8.0. It allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. The CVSS score is 5.3, and the severity is MEDIUM. Defenders should assess exposure and apply the patch to prevent code injection attacks. The vulnerability has been publicly disclosed and may be utilized. The official CVE record and NVD entry list TallCMS as the affected package name and version (up to 4.8.0).
Defensive priority
Apply patch to resolve code injection vulnerability in TallCMS PluginManager
Recommended defensive actions
- Apply the patch fdc18f4c6a36134f8986ca1d7e4e97092e3deb93 to resolve the code injection vulnerability
- Review and update TallCMS to a version beyond 4.8.0 if available
- Monitor systems using TallCMS for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The official CVE record and NVD entry list TallCMS as the affected package name and version (up to 4.8.0). The CVE‑Program JSON source item also contains the package name 'TallCMS'. The vulnerability affects the ThemeManager.php file in the PluginManager component of TallCMS up to version 4.8.0. It allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. The CVSS score is 5.3, and the severity is MEDIUM.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105329 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105329
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105329 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105329
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
TallCMS PluginManager ThemeManager.php code injection
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105329.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413543
Supplemental source - vdb-entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413543/cti
Supplemental source - signature, permissions-required
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105329
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/979800
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/tallcms/tallcms/issues/122
Supplemental source - exploit, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/tallcms/tallcms/pull/124
Supplemental source - issue-tracking, patch
-
Source reference
Unverified legacy reference
URL: https://github.com/beegoodit/tallcms/commit/fdc18f4c6a36134f8986ca1d7e4e97092e3deb93
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.