CVE-2018-17126: Chshcms Cscms
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
Affected products
- Chshcms Cscms: version 4.1 only
Published 2018-09-17. Last modified 2026-06-17.