Code Injection in mtrano APENCMS Template Engine
CVE-2026-95501
4.8MEDIUM
What is CVE-2026-95501?
A vulnerability has been identified in the mtrano APENCMS Template Engine that affects the 'eval' function in the cms/weasel.php file. This weakness allows an attacker to manipulate the argument $_CMS['site'], leading to potential code injection attacks. The nature of the attack enables exploitation from a remote location. With the exploit already made public, it poses a significant threat to systems running the affected version. mtrano's rolling release system complicates the tracking of version-specific vulnerabilities, as details on patches or updates may not be disclosed promptly.
Affected Version(s)
APENCMS 6546096d354153309693efabb9a0d824628ed4f5
