CVE-2023-36212: Totalcms Total CMS

High severity, CVSS 8.8. EPSS: 25.8% chance of exploitation in the next 30 days.

File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function.

Affected products

Published 2023-08-03. Last modified 2026-06-17.