AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-25T21:17:45.957Z and has not been modified since then. The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafte [truncated]
MacCMS10's admin template editor is vulnerable to remote code execution due to a blacklist regex omission. An authenticated administrator could inject a payload to achieve remote code execution. The vendor has released a patch in commit 71ad3bb29570e110d8e973acff68040a3050ddf0. Affected administrators should verify and apply the patch. The vulnerability allows for remote code execution via a crafted templ [truncated]