CVE-2026-64796
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enf
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 22, 2026 · Last modified: Jul 22, 2026 · CWE-284
Not enough EPSS history yet.
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-64794——
——0User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.6hCVE-2026-64793——
——0Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.6hCVE-2026-64791——
——0Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.6hCVE-2026-63685——
——0Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.6hCVE-2026-63684——
——0Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.6hCVE-2026-63280——
——0Conditions administration did not consistently enforce tokens and component/mapped-item permissions.6h