CVE-2026-39387 Details
Description
BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to sanitize the tpl (template) parameter during page creation and updates. This parameter is passed directly to a require_once() statement without path validation. An authenticated administrator can exploit this by injecting path traversal sequences (../) into the tpl value to escape the intended theme directory and include arbitrary files — specifically, files from the server's media/ directory. When combined with the file upload functionality, this becomes a full RCE chain: an attacker can first upload a file with embedded PHP code (e.g., disguised as image data), then use the path traversal vulnerability to include that file via require_once(), executing the embedded code with web server privileges. This issue has been fixed in version 2.1.3.
A critical local file inclusion (LFI) vulnerability has been identified in BoidCMS versions prior to 2.1.3. This vulnerability allows authenticated administrators to exploit the tpl parameter, leading to remote code execution (RCE). The issue arises because the application fails to properly sanitize the tpl parameter during page creation and updates, allowing path traversal sequences to be injected. This enables the inclusion of arbitrary files from the server's media directory. When combined with the file upload functionality, this vulnerability can be exploited to execute embedded PHP code with web server privileges.
Users are advised to update to BoidCMS version 2.1.3 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 | CISA-ADP | ExploitMitigationVendor Advisory |
| https://github.com/BoidCMS/BoidCMS/releases/tag/v2.1.3 | [email protected] | ProductRelease Notes |
| https://github.com/BoidCMS/BoidCMS/security/advisories/GHSA-45xp-xw54-6cv6 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| boidcms boidcms | < 2.1.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | Initial Analysis | [email protected] |
| Apr 15, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | New CVE Received | [email protected] |