CVE-2026-7508

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The code repository of the project has not been active for many years. This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

No configuration.

History

30 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 23:16

Updated : 2026-05-01 15:26


NVD link : CVE-2026-7508

Mitre link : CVE-2026-7508

CVE.ORG link : CVE-2026-7508


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')