ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 07 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liweiyi
Liweiyi chestnutcms |
|
| Vendors & Products |
Liweiyi
Liweiyi chestnutcms |
Thu, 07 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ChestnutCMS v1.5.10 SQL Injection via cms_content tag | |
| Weaknesses | CWE-89 |
Thu, 07 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-07T13:59:05.880Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36458
No data.
Status : Deferred
Published: 2026-05-07T15:16:05.523
Modified: 2026-05-07T15:53:01.027
Link: CVE-2026-36458
No data.
OpenCVE Enrichment
Updated: 2026-05-07T16:30:15Z
Weaknesses