CVE-2022-50898

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kalyan02:nanocms:0.4:*:*:*:*:*:*:*

History

29 Jan 2026, 14:16

Type Values Removed Values Added
CWE CWE-94

28 Jan 2026, 20:07

Type Values Removed Values Added
CWE CWE-434
First Time Kalyan02
Kalyan02 nanocms
CPE cpe:2.3:a:kalyan02:nanocms:0.4:*:*:*:*:*:*:*
References () https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt - () https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt - Third Party Advisory
References () https://github.com/kalyan02/NanoCMS - () https://github.com/kalyan02/NanoCMS - Product
References () https://www.exploit-db.com/exploits/50997 - () https://www.exploit-db.com/exploits/50997 - Exploit
References () https://www.vulncheck.com/advisories/nanocms-remote-code-execution-rce-authenticated - () https://www.vulncheck.com/advisories/nanocms-remote-code-execution-rce-authenticated - Third Party Advisory

14 Jan 2026, 20:15

Type Values Removed Values Added
References () https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt - () https://github.com/ishell/Exploits-Archives/blob/master/2009-exploits/0904-exploits/nanocms-multi.txt -

13 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:15

Updated : 2026-01-29 14:16


NVD link : CVE-2022-50898

Mitre link : CVE-2022-50898

CVE.ORG link : CVE-2022-50898


JSON object : View

Products Affected

kalyan02

  • nanocms
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type