CVE-2026-61524 is a high-severity vulnerability in WebsiteBaker CMS that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive. The vulnerability exists in the module installation feature and requires verification of affected versions and remediation steps. Affected product deployments should be verified, and owners assigned for follow-up. Official advisor [truncated]
CVE-2026-61523 is a high-severity code injection vulnerability in WebsiteBaker CMS before version 2.13.10. Authenticated administrators can inject arbitrary PHP code through the Droplets editor, which is then written to a publicly accessible PHP file. This allows unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file. The vulnerability is highly severe, w [truncated]