Description
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
Published: 2026-01-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:websitebaker:websitebaker:2.13.0:*:*:*:*:*:*:*

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Websitebaker
Websitebaker websitebaker
Vendors & Products Websitebaker
Websitebaker websitebaker

Thu, 15 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
Title WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Websitebaker Websitebaker
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:28:34.909Z

Reserved: 2026-01-14T14:39:44.738Z

Link: CVE-2021-47788

cve-icon Vulnrichment

Updated: 2026-01-16T15:53:32.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-16T00:16:22.263

Modified: 2026-01-30T01:02:28.600

Link: CVE-2021-47788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T13:42:29Z

Weaknesses