PT-2026-63507 · Sorcerer · Sourcerer

CVE-2026-64796

·

Published

2026-07-22

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcerer extension (affected versions not specified)
Description Multiple code injection vectors exist within the extension. The Free version fails to verify that both the article creator and the last modifier possess Super User privileges before executing PHP code within an article. The Pro version does not consistently enforce permissions for CSS, JavaScript, and PHP across tags, attributes, files, and article owners. Additionally, PHP include attributes may allow escaping the configured include folder, and certain executable script or style variants can bypass detection mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64796

Affected Products

Sourcerer