CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-105985: cms 5.0.0 to before 5.11.0

CVE-2026-105985. CVSS 3.1 base score 8.8 (HIGH, Source advisory).

Affected technology

cms · 5.0.0 to before 5.11.0
craftcms

Description’s affected range: 5.10.13.2

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run code remotely under the conditions described by the source. Source advisory’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-1336
CCR priority
35.2 /100 (P4)
CVSS 3.1
8.8 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-105985.html