VYPR
Vendor

Slah

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-30993CriApr 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

  • CVE-2026-30995HigApr 15, 2026
    risk 0.56cvss 8.6epss 0.00

    Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_ver.php endpoint.

  • CVE-2026-30994HigApr 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access sensitive information, including active session credentials.