PT-2026-33109 · Slah Cms · Slah Cms

CVE-2026-30993

·

Published

2026-04-15

·

Updated

2026-04-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Slah CMS versions prior to 1.5.1
Description Remote code execution is possible via crafted input processed by the session() function located in 'config.php'.
Recommendations Update to a version newer than 1.5.0. As a temporary workaround, consider restricting access to the session() function in 'config.php' until a patch is applied.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30993

Affected Products

Slah Cms