PT-2026-41462 · Textpattern · Textpattern Cms

Mevlüt Akçam

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2021-47976

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-47976

Affected Products

Textpattern Cms