CVE-2020-21359: Maccms

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

Affected products

  • Maccms Maccms: version 10.0 only

Published 2021-08-11. Last modified 2026-06-17.