Showing 2 vulnerabilities on this page for Schlix CMS

Signals CISA KEV Ransomware Nuclei
Schlix vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger execution by accessing the About tab of the installed extension.

CWE-94May 15, 2026
CVSS8.7v4.0EPSS0.71%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)

Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.

CWE-79Jan 16, 2026
CVSS5.1v4.0EPSS0.248%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX