CVE-2026-39387Disclosure(boidcms / boidcms)

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to sanitize the tpl (template) parameter during page creation and updates. This parameter is passed directly to a require_once() statement without path validation. An authenticated administrator can exploit this by injecting path traversal sequences (../) into the tpl value to escape the intended theme directory and include arbitrary files — specifically, files from the server's media/ directory. When combined with the file upload functionality, this becomes a full RCE chain: an attacker can first upload a file with embedded PHP code (e.g., disguised as image data), then use the path traversal vulnerability to include that file via require_once(), executing the embedded code with web server privileges. This issue has been fixed in version 2.1.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • boidcms

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-15)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
boidcms

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-14: 1Mentions · 2026-04-15: 3Technical Details · 2026-04-15: 104-1404-15
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-141
General1
2026-04-153
Disclosure3
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-39387 BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a cri… https://www.cve.org/CVERecord?id=CVE-2026-39387

    Post summary

    The text announces that BoidCMS versions before 2.1.3 are vulnerable to CVE‑2026‑39387, but it offers no proof‑of‑concept, exploit details, or patch information.

    0001089
    57.2K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-39387: BoidCMS Template Parameter Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04cb9c00

    Post summary

    A short article headline announcing the BoidCMS Template Parameter Bug (CVE‑2026‑39387) and encouraging readers to respond, but without providing technical, exploit, or patch details.

    0000024
    28 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39387 Local File Inclusion and Remote Code Execution in BoidCMS Versions Prior to 2.1.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39387

    Post summary

    The text announces the existence of CVE-2026-39387, detailing an LFI and RCE vulnerability in BoidCMS versions before 2.1.3, without mentioning PoC, exploitation, or mitigation.

    0000042
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    General

    ⚠️ HIGH — CVE-2026-39387 BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. … CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-39387 #HP #CyberSecurity #InfoSec

    Post summary

    The post announces a high severity CVE for BoidCMS with a CVSS score of 7.2 and provides a link to further analysis, but offers no additional technical or actionable details.

    000001
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appboidcmsboidcms---

Explore more