CVE-2023-53892
Blackcat CMS 1.4 Remote Code Execution via Jquery Plugin Manager
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the jquery plugin manager. Attackers can upload a zip file with a PHP shell script and execute arbitrary system commands by accessing the uploaded plugin's PHP file with a 'code' parameter.
| CWE | CWE-434 |
| Vendor | blackcat-cms |
| Product | blackcat cms |
| Published | Dec 15, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for blackcat-cms blackcat cms
Be the first to know when new unknown vulnerabilities affecting blackcat-cms blackcat cms are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
blackcat-cms / Blackcat CMS
1.4
References
Credits
Mirabbas Ağalarov