CVE-2024-48180: Classcms
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
Affected products
- Classcms Classcms: up to and including 4.8
Published 2024-10-16. Last modified 2026-06-17.