Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter to create modules that execute arbitrary commands when invoked. | |
| Title | Evolution CMS 3.1.6 Authenticated Remote Code Execution via Module Creation | |
| First Time appeared |
Evo
Evo evolution Cms |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:evo:evolution_cms:3.1.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Evo
Evo evolution Cms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T16:09:28.995Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47939
Updated: 2026-05-11T16:08:49.957Z
Status : Deferred
Published: 2026-05-10T13:16:30.233
Modified: 2026-05-12T14:24:15.210
Link: CVE-2021-47939
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:15:14Z