PatchSiren

TallCMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM TallCMS CVE published 2026-10-05

CVE-2026-105329

A code injection vulnerability was determined in TallCMS up to 4.8.0, affecting the PluginManager component's ThemeManager.php file. This issue allows remote attackers to inject code, with a publicly disclosed exploit that may be utilized. The patch for this issue is fdc18f4c6a36134f8986ca1d7e4e97092e3deb93. Defenders should assess exposure and apply the patch to prevent code injection attacks. The vulner [truncated]