PatchSiren

WebsiteBaker Org e.V. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WebsiteBaker Org e.V. CVE published 2026-08-03

CVE-2026-61524

CVE-2026-61524 is a high-severity vulnerability in WebsiteBaker CMS that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive. The vulnerability exists in the module installation feature and requires verification of affected versions and remediation steps. Affected product deployments should be verified, and owners assigned for follow-up. Official advisor [truncated]

HIGH WebsiteBaker Org e.V. CVE published 2026-08-03

CVE-2026-61523

CVE-2026-61523 is a high-severity code injection vulnerability in WebsiteBaker CMS before version 2.13.10. Authenticated administrators can inject arbitrary PHP code through the Droplets editor, which is then written to a publicly accessible PHP file. This allows unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file. The vulnerability is highly severe, w [truncated]