Code Injection Vulnerability in WebsiteBaker CMS by WebsiteBaker
CVE-2026-61523

8.6HIGH

Key Information:

Vendor
CVE Published:
3 August 2026

What is CVE-2026-61523?

A code injection vulnerability exists in the Droplets editor of WebsiteBaker CMS versions prior to 2.13.10. This flaw allows authenticated administrators to submit malicious content through the droplets Code field, leading to the injection of arbitrary PHP code. The unsanitized code is directly written to a publicly accessible PHP file, enabling attackers to exploit this vulnerability. By saving a PHP web shell via the save_droplet handler to a predictable path in the modules directory, unauthorized users can execute remote commands by sending HTTP requests to the vulnerable script, potentially compromising the entire server.

Affected Version(s)

WebsiteBaker CMS 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Benjamin Agyapong Asare
.