PT-2026-36316 · Unknown · Maccms Pro

Qingyunsec

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7578

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MacCMS Pro versions prior to 2022.1.4
Description A flaw in the Plugin Installation Handler component allows for unrestricted file upload. A remote attacker can exploit this by manipulating the install() function within the '/admi.php/admin/addon/add.html' endpoint.
Recommendations Update to a version later than 2022.1.3. As a temporary workaround, restrict access to the '/admi.php/admin/addon/add.html' endpoint or disable the install() function in the Plugin Installation Handler.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7578

Affected Products

Maccms Pro