Code Injection in mtrano APENCMS Template Engine
CVE-2026-95501

4.8MEDIUM

Key Information:

Vendor

Mtrano

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95501?

A vulnerability has been identified in the mtrano APENCMS Template Engine that affects the 'eval' function in the cms/weasel.php file. This weakness allows an attacker to manipulate the argument $_CMS['site'], leading to potential code injection attacks. The nature of the attack enables exploitation from a remote location. With the exploit already made public, it poses a significant threat to systems running the affected version. mtrano's rolling release system complicates the tracking of version-specific vulnerabilities, as details on patches or updates may not be disclosed promptly.

Affected Version(s)

APENCMS 6546096d354153309693efabb9a0d824628ed4f5

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

milocat (VulDB User)
VulDB CNA Team
.