Critical Remote Code Execution Vulnerability in Evolution CMS Disclosed

Critical Remote Code Execution Vulnerability in Evolution CMS Disclosed

First seen 10 May 2026, 20:03 UTC Feedlydb.gcve.eucve.reportwww.redpacketsecurity.comvuldb.com+1 88% similarity 67.5

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability (CVE-2021-47939) has been identified in Evolution CMS 3.1.6, allowing authenticated users with module creation permissions to execute arbitrary system commands. The vulnerability is exploited by sending POST requests to /manager/index.php with malicious PHP code in the 'post' parameter. Currently, there is no evidence of public exploitation or a proof-of-concept available. Affected users include those with module creation permissions, and the CVSS base score assigned is 8.8, indicating a high severity. No patches have been released as of now, and security experts recommend restricting module creation permissions and implementing input validation. The vulnerability was published on May 10, 2026, alongside another CVE for a different CMS (CVE-2021-47938).

Key Points: • CVE-2021-47939 allows remote code execution in Evolution CMS 3.1.6. • Attackers can exploit the vulnerability via crafted POST requests to /manager/index.php. • No patches are available; immediate action is recommended to restrict permissions.

ThreatCluster AI

Timeline

2026-05-10
CVE-2021-47939 published
A remote code execution vulnerability in Evolution CMS 3.1.6 was disclosed, affecting authenticated users with module creation permissions.
Feedly
2026-05-10
CVE-2021-47938 published
Another remote code execution vulnerability was disclosed in ImpressCMS 1.4.2, allowing similar exploitation methods.
cve.report

Community

Browse all →

Tracked Entities in This Story