HIGH
Kunstmaan
CVE published 2026-10-07
CVE-2026-104890
An authenticated administrator can bypass the MediaBundle extension blacklist in Kunstmaan CMS versions before 7.3.2 to upload executable PHP files, potentially leading to remote code execution. This vulnerability allows an attacker to execute arbitrary code on the server, which can lead to a complete compromise of the system. The vulnerability is fixed in version 7.3.2, and administrators should prioriti [truncated]