THREATOPS
THREAT OPSThreat News › Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read

Flextype v1.0.0-alpha.3 Stored Filesystem Shortcode Allows Arbitrary File Read

lowfulldisclosurePublished 2026-09-04

<p>Posted by Ron E on Sep 03</p>Description<br /> <br /> Flextype CMS v1.0.0-alpha.3 contains an arbitrary file-read vulnerability<br /> in its stored shortcode processing functionality. Attacker-controlled entry<br /> fields are automatically processed by the shortcode parser when global<br /> shortcode processing is enabled.<br /> <br /> The built-in filesystem shortcode accepts a file path and

Original source: https://seclists.org/fulldisclosure/2026/Sep/25