THREAT OPS › Threat News › Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion
<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS contains a remote code execution vulnerability in the<br /> interaction between the Entries API and Shortcodes::registerShortcodes().<br /> The /api/v1/entries endpoint accepts an attacker-controlled entry<br /> identifier that can contain path traversal sequences, allowing content<br /> containing PHP code to be written outside
Original source: https://seclists.org/fulldisclosure/2026/Sep/27