A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
Affected Vendors & Products
References
History
Sun, 26 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | GreenCMS index.php themeadd unrestricted upload | |
| First Time appeared |
Greencms
Greencms greencms |
|
| Weaknesses | CWE-284 CWE-434 |
|
| CPEs | cpe:2.3:a:greencms:greencms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Greencms
Greencms greencms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-26T13:30:09.575Z
Reserved: 2026-04-25T16:01:42.025Z
Link: CVE-2026-7044
No data.
No data.
No data.
OpenCVE Enrichment
No data.