PT-2026-36316 · Unknown · Maccms Pro

Qingyunsec

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7578

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MacCMS Pro versions prior to 2022.1.4
Description A weakness in the Plugin Installation Handler component allows for unrestricted file upload. This issue occurs within the install() function of the file '/admi.php/admin/addon/add.html' and can be exploited remotely.
Recommendations Update to a version later than 2022.1.3. As a temporary workaround, restrict access to the '/admi.php/admin/addon/add.html' file or disable the install() function within the Plugin Installation Handler.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-7578

Affected Products

Maccms Pro