WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server. | |
| Title | WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated) | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-15T23:25:40.313Z
Reserved: 2026-01-14T14:39:44.738Z
Link: CVE-2021-47788
No data.
Status : Received
Published: 2026-01-16T00:16:22.263
Modified: 2026-01-16T00:16:22.263
Link: CVE-2021-47788
No data.
OpenCVE Enrichment
No data.