CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-46958

Critical · CVSS 9.8

lmxcms — Remote Code Execution via crafted script (Code Injection)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
NVD-CWE-noinfo, CWE-94

Description

An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.

Search profile — drives PoC discovery

Symbols admin.phplmxcmsv1.41durian5201314
Keywords CVE-2023-46958lmxcmslmxcms 1.41admin.php RCEarbitrary code execution lmxcmslmxcms exploitCWE-94 lmxcms
Versions: 1.41

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z