VYPR

Blackcatcms

by Blackcatdevelopment

Source repositories

CVEs (2)

  • CVE-2023-53892Dec 15, 2025
    risk 0.00cvss epss 0.01

    Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.

  • CVE-2023-53891Dec 15, 2025
    risk 0.00cvss epss 0.00

    Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.