THREATOPS
THREAT OPSThreat News › Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

lowfulldisclosurePublished 2026-09-04

<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS contains a remote code execution vulnerability in the<br /> interaction between the Entries API and Shortcodes::registerShortcodes().<br /> The /api/v1/entries endpoint accepts an attacker-controlled entry<br /> identifier that can contain path traversal sequences, allowing content<br /> containing PHP code to be written outside

Original source: https://seclists.org/fulldisclosure/2026/Sep/27