Metrics
Affected Vendors & Products
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutralization of directives in dynamically evaluated code. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-04-20T15:00:22.525Z
Updated: 2026-04-20T16:14:56.950Z
Reserved: 2026-04-20T05:58:31.133Z
Link: CVE-2026-6652
Updated: 2026-04-20T16:09:29.534Z
Status : Received
Published: 2026-04-20T16:16:56.013
Modified: 2026-04-20T16:16:56.013
Link: CVE-2026-6652
No data.