CVE-2026-73679
published 2026-08-14CVE-2026-73679: ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary…
PriorityP350high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.61%
47.8th percentile
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier sanitization, and the payload is triggered on every frontend page load through the preload event system.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| impresscms | impresscms | <= 2.0.3 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ImpressCMS up to 2.0.3 Custom Tag renderWithPhp code injection
vuldb·2026-08-14·CVSS 7.2
CVE-2026-73679 [HIGH] ImpressCMS up to 2.0.3 Custom Tag renderWithPhp code injection
A vulnerability described as problematic has been identified in ImpressCMS up to 2.0.3. Affected by this issue is the function renderWithPhp of the component Custom Tag Module. Executing a manipulation can lead to code injection.
The identification of this vulnerability is CVE-2026-73679. The attack may be launched remotely. There is no exploit available.
GHSA
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload
ghsa_unreviewed·2026-08-14
CVE-2026-73679 [HIGH] CWE-94 ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier sanitization, and the payload is triggered on every frontend page load through the preload event system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published