Remote Code Execution Vulnerability in MacCMS10 by MagicBlack
CVE-2026-71232

7.2HIGH

Key Information:

Vendor

Magicblack

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71232?

The vulnerability in MacCMS10's admin template editor arises from an inadequate filter that fails to block critical PHP functions such as exec and passthru. This oversight allows an authenticated administrator to exploit the system by injecting malicious payloads within template conditions using ThinkPHP's template tag system. With the ability to execute commands on the server, attackers can potentially gain full control over the affected environment. A fix has been implemented to address these filtering deficiencies, ensuring a more secure template handling process.

Affected Version(s)

maccms10 0 < 10

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mirdavlatov Mira'zam
.