LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2021-47939

CVE-2021-47939 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 10, 2026

Evolution CMS - Remote Code Execution

Published: May 10, 2026Updated: May 10, 2026Remote Exploitable

Overview

Evolution CMS 3.1.6 contains a remote code execution caused by PHP code injection in module parameters via POST requests to /manager/index.php, letting authenticated users with module creation permissions execute arbitrary system commands.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Authenticated users with module creation permissions can execute arbitrary system commands, potentially leading to full system compromise.

Mitigation

Update to the latest version of Evolution CMS.

Details

CVE ID
CVE-2021-47939
Severity
High
CVSS Score
8.8
Type
command_injection
Status
new

CWE

  • CWE-94

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H