A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
History

Mon, 27 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Apr 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Title GreenCMS index.php themeadd unrestricted upload
First Time appeared Greencms
Greencms greencms
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:greencms:greencms:*:*:*:*:*:*:*:*
Vendors & Products Greencms
Greencms greencms
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-04-26T13:30:09.575Z

Updated: 2026-04-27T16:41:31.003Z

Reserved: 2026-04-25T16:01:42.025Z

Link: CVE-2026-7044

cve-icon Vulnrichment

Updated: 2026-04-27T16:41:26.651Z

cve-icon NVD

Status : Deferred

Published: 2026-04-26T22:17:32.057

Modified: 2026-04-27T18:50:06.087

Link: CVE-2026-7044

cve-icon Redhat

No data.