CVE-2024-44724: Autocms Project Autocms

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.

Affected products

Published 2024-09-09. Last modified 2026-06-17.