CVE-2026-102771Medium· 4.7▾ SunlitA security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. T…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of the component Email Template. The manipulation leads to improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-75979Medium· 6.3A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta
CVE-2026-19929Medium· 6.3A vulnerability was identified in OpenBoxes up to 0.9.6
CVE-2026-84462High· 8.6Zammad is a web based open source helpdesk/customer support system
CVE-2026-63728Medium· 6.3Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature
CVE-2026-97359Critical· 10.0HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename
CVE-2026-73858Medium· 5.3Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool