HIGHVulnerability

CVE-2026-73679

ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier sanitization, and the payload is triggered on every frontend page load through the preload event system.

Properties

severity
HIGH
score
7.2
cve_id
CVE-2026-73679
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-14T19:18:01.610
last_modified
2026-08-26T16:57:52.167

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73679 — Ninja Signal Threat Intelligence | Ninja Signal