CVE-2026-39387

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to sanitize the tpl (template) parameter during page creation and updates. This parameter is passed directly to a require_once() statement without path validation. An authenticated administrator can exploit this by injecting path traversal sequences (../) into the tpl value to escape the intended theme directory and include arbitrary files — specifically, files from the server's media/ directory. When combined with the file upload functionality, this becomes a full RCE chain: an attacker can first upload a file with embedded PHP code (e.g., disguised as image data), then use the path traversal vulnerability to include that file via require_once(), executing the embedded code with web server privileges. This issue has been fixed in version 2.1.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:boidcms:boidcms:*:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) BoidCMS es un CMS de ficheros planos de código abierto, basado en PHP, para construir sitios web y blogs sencillos, usando JSON como su base de datos. Las versiones anteriores a la 2.1.3 son vulnerables a un ataque crítico de Inclusión Local de Ficheros (LFI) a través del parámetro tpl, lo que puede conducir a la Ejecución Remota de Código (RCE). La aplicación no sanitiza el parámetro tpl (plantilla) durante la creación y actualización de páginas. Este parámetro se pasa directamente a una sentencia require_once() sin validación de ruta. Un administrador autenticado puede explotar esto inyectando secuencias de salto de ruta (../) en el valor de tpl para escapar del directorio de tema previsto e incluir ficheros arbitrarios - específicamente, ficheros del directorio media/ del servidor. Cuando se combina con la funcionalidad de subida de ficheros, esto se convierte en una cadena completa de RCE: un atacante puede primero subir un fichero con código PHP incrustado (por ejemplo, disfrazado como datos de imagen), luego usar la vulnerabilidad de salto de ruta para incluir ese fichero a través de require_once(), ejecutando el código incrustado con privilegios de servidor web. Este problema ha sido solucionado en la versión 2.1.3.

23 Apr 2026, 17:35

Type Values Removed Values Added
References () https://github.com/BoidCMS/BoidCMS/releases/tag/v2.1.3 - () https://github.com/BoidCMS/BoidCMS/releases/tag/v2.1.3 - Product, Release Notes
References () https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 - () https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:boidcms:boidcms:*:*:*:*:*:*:*:*
First Time Boidcms
Boidcms boidcms

15 Apr 2026, 15:16

Type Values Removed Values Added
References () https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 - () https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 -

14 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 23:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-39387

Mitre link : CVE-2026-39387

CVE.ORG link : CVE-2026-39387


JSON object : View

Products Affected

boidcms

  • boidcms
CWE
CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')