WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.
References
| Link | Resource |
|---|---|
| https://websitebaker.org/ | Product |
| https://www.exploit-db.com/exploits/50310 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/websitebaker-remote-code-execution-rce-authenticated | Third Party Advisory |
| https://www.exploit-db.com/exploits/50310 | Exploit VDB Entry |
Configurations
History
30 Jan 2026, 01:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Websitebaker
Websitebaker websitebaker |
|
| CPE | cpe:2.3:a:websitebaker:websitebaker:2.13.0:*:*:*:*:*:*:* | |
| References | () https://websitebaker.org/ - Product | |
| References | () https://www.exploit-db.com/exploits/50310 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/websitebaker-remote-code-execution-rce-authenticated - Third Party Advisory |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/50310 - |
16 Jan 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 00:16
Updated : 2026-01-30 01:02
NVD link : CVE-2021-47788
Mitre link : CVE-2021-47788
CVE.ORG link : CVE-2021-47788
JSON object : View
Products Affected
websitebaker
- websitebaker
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
