What is CVE-2026-67595?
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload in the security OTP email Blade template, enabling remote code execution in browsers with JavaScript enabled. Immediate CMS update is strongly advised.
Azərbaycanca: VaahCMS 2.0.0 - 2.3.4 versiyalarında, təhlükəsizlik OTP e-poçt şablonuna yerləşdirilmiş zərərli, obfuskasiya olunmuş JavaScript tapılıb. Bu, JavaScript aktiv olan brauzerlərdə uzaqdan kod icrasına səbəb ola bilir. Dərhal VaahCMS-i son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of VaahCMS are affected by CVE-2026-67595?
This vulnerability affects VaahCMS versions 2.0.0 through 2.3.4.
How is CVE-2026-67595 exploited?
The vulnerability is exploited via a malicious obfuscated JavaScript payload placed in the security OTP email template.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.