CVE-2026-5987
Received Received - Intake
Improper Neutralization in Sanluan PublicCMS FreeMarker Allows Remote Attack

Publication date: 2026-04-09

Last updated on: 2026-04-29

Assigner: VulDB

Description
A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker Template Handler. Such manipulation leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-09
Last Modified
2026-04-29
Generated
2026-05-07
AI Q&A
2026-04-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sanluan publiccms to 6.202506.d (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
CWE-791 The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Sanluan PublicCMS up to version 6.202506.d, specifically in the function AbstractFreemarkerView.doRender within the FreeMarker Template Handler component. It involves improper neutralization of special elements used in the template engine, which can be manipulated remotely by an attacker.


How can this vulnerability impact me? :

The vulnerability allows remote attackers to exploit the improper neutralization of special elements in the template engine, potentially leading to unauthorized actions or information disclosure. The exact impact depends on the context of use, but it may compromise the integrity and confidentiality of the affected system.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart