CVE-2018-10740: Axublog

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file.

Affected products

  • Axublog Axublog: version 1.1.0 only

Published 2018-05-04. Last modified 2026-06-17.