Description
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 26 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | GreenCMS index.php themeadd unrestricted upload | |
| First Time appeared |
Greencms
Greencms greencms |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:greencms:greencms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Greencms
Greencms greencms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-26T13:30:09.575Z
Reserved: 2026-04-25T16:01:42.025Z
Link: CVE-2026-7044
No data.
No data.
No data.
OpenCVE Enrichment
No data.