Code Injection Vulnerability in Sanluan PublicCMS Affected by Template Engine Manipulation
CVE-2026-5987
Key Information:
Badges
What is CVE-2026-5987?
A security vulnerability has been identified in Sanluan PublicCMS versions up to 6.202506.d, specifically within the AbstractFreemarkerView.doRender function in the FreeMarker Template Handler component. This flaw allows for improper handling of special elements in templates, which can expose the system to remote code injection attacks. The vulnerability has been publicly acknowledged, with no remediation measures communicated by the project maintainers. Users of affected versions are urged to assess their exposure and implement security best practices.
Affected Version(s)
PublicCMS 4.0.202506.a
PublicCMS 4.0.202506.b
PublicCMS 5.202506.a
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
