CVE-2026-71232: Magicblack MACCMS10
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log.
Affected products
- Magicblack MACCMS10: up to and including 10
Published 2026-08-05. Last modified 2026-08-26.