HIGH
magicblack
CVE published 2026-08-05
CVE-2026-71232
MacCMS10's admin template editor is vulnerable to remote code execution due to a blacklist regex omission. An authenticated administrator could inject a payload to achieve remote code execution. The vendor has released a patch in commit 71ad3bb29570e110d8e973acff68040a3050ddf0. Affected administrators should verify and apply the patch. The vulnerability allows for remote code execution via a crafted templ [truncated]