Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.
History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Slah Cms
Slah Cms slah Cms
Vendors & Products Slah Cms
Slah Cms slah Cms

Wed, 15 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Session Function in Slah CMS
Weaknesses CWE-94

Wed, 15 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Description Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-15T17:24:08.072Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-30993

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-15T18:16:59.913

Modified: 2026-04-15T18:16:59.913

Link: CVE-2026-30993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:02:31Z