CVE-2026-61523: Websitebaker Org E.v Websitebaker CMS
High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.
Affected products
- Websitebaker Org E.v Websitebaker CMS: before 2.13.10 (fixed in 2.13.10)
Published 2026-08-03. Last modified 2026-09-09.