GHSA-77f2-mm55-xvp4HighCVSS 8.8

TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows...

Published
May 16, 2026
Last Modified
May 16, 2026

🔗 CVE IDs covered (1)

📋 Description

TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution.

🔗 References (6)