← Vulnerability feed

Vulnerability record · CVE-2019-9829 · published 15 March 2019

CVE-2019-9829: Maccms inclusion from untrusted sphere vulnerability

MMaccms · Maccms

Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

8.8 CVSS 3.0 High EPSS 2.0% · top 20.1% CWE-829 · Inclusion from untrusted sphere
8.8CVSS 3.0 base score, v2 6.5
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9829 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45786Maccms improper authentication vulnerabilityIn maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.EPSS 1.2%9.8CVE-2020-21359Maccms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu…EPSS 1.7%9.8CVE-2017-17733Maccms vulnerabilityMaccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.EPSS 44%9.1CVE-2025-28091Maccms server-side request forgery (ssrf) vulnerabilitymaccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.EPSS 0.43%9.1CVE-2025-28089Maccms server-side request forgery (ssrf) vulnerabilitymaccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.EPSS 0.43%9.1CVE-2025-28090Maccms server-side request forgery (ssrf) vulnerabilitymaccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.EPSS 0.42%8.8CVE-2022-47872Maccms server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted p…EPSS 0.87%8.8CVE-2020-21386Maccms cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2019-9829), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.