PT-2026-33109 · Slah Cms · Slah Cms

Published

2026-04-15

·

Updated

2026-04-17

·

CVE-2026-30993

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slah CMS versions prior to 1.5.1
Description Remote code execution is possible via crafted input processed by the session() function located in 'config.php'.
Recommendations Update to a version newer than 1.5.0. As a temporary workaround, consider restricting access to the session() function in 'config.php' until a patch is applied.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-30993

Affected Products

Slah Cms