Skip to content
Multiple CVEs in Magnolia CMS Expose Users to Remote Code Execution

Multiple CVEs in Magnolia CMS Expose Users to Remote Code Execution

First seen 22 Sep 2026, 22:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 23:57 UTC
  • Magnolia CMS versions 6.2.3 and below are vulnerable to multiple critical CVEs.
  • Exploitation methods include CSRF, server-side template injection, and YAML deserialization.
  • Patches are available, but PoCs for some vulnerabilities indicate potential for active exploitation.

A series of vulnerabilities affecting Magnolia CMS versions 6.2.3 and below have been disclosed, including CVE-2021-46366, CVE-2021-46362, CVE-2021-46361, and CVE-2021-46364. These vulnerabilities allow unauthorized access and remote code execution through various attack vectors such as CSRF, server-side template injection, and YAML deserialization. The vulnerabilities were published on February 11, 2022, with proof-of-concept (PoC) code for CVE-2021-46364 released on November 24, 2023. Users of affected systems are at risk of credential theft and arbitrary code execution. Vendors have issued advisories for remediation, but the exploitation status varies across the CVEs. Security professionals are urged to apply patches and monitor for signs of exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-02-11
CVE-2021-46361 published
A vulnerability in FreeMarker Filter allows arbitrary code execution in Magnolia CMS.
Sploitus
2022-02-11
CVE-2021-46362 published
Server-side template injection vulnerability in Magnolia CMS allows unauthorized code execution.
Sploitus
2022-02-11
CVE-2021-46364 published
YAML deserialization vulnerability in Magnolia CMS enables remote code execution via Snake YAML parser.
Sploitus
2022-02-11
CVE-2021-46366 published
CSRF vulnerability allows credential theft in Magnolia CMS login page.
Sploitus
2023-11-24
First public PoC for CVE-2021-46364
Public proof-of-concept code was released, demonstrating the exploitability of the YAML deserialization vulnerability.
Sploitus
2024-02-14
First public PoC for CVE-2021-46362 and CVE-2021-46366
Proof-of-concept code for both vulnerabilities was made public, increasing the risk of exploitation.
Sploitus
2024-02-17
First public PoC for CVE-2021-46361
A proof-of-concept for the FreeMarker Filter vulnerability was released, highlighting its exploitability.
Sploitus

More articles in this cluster (4)

Following this threat?

Track CVE-2021-46361 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed