CVE Explorer
CVE-2026-12257
Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby comp
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"CMS","vendor":"Mura Software","versions":[{"status":"affected","version":"10.0.712"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9c7d5d0629af9246baa1ed7687fa7cfc69430153a0c1dd5cfa9bb7b3f73f7f65 · sha256:27880dba1254afcb… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9c7d5d0629af9246baa1ed7687fa7cfc69430153a0c1dd5cfa9bb7b3f73f7f65 · sha256:27880dba1254afcb… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94 Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9c7d5d0629af9246baa1ed7687fa7cfc69430153a0c1dd5cfa9bb7b3f73f7f65 · sha256:27880dba1254afcb… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/remote-code-execution-mura-softwares-cms"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9c7d5d0629af9246baa1ed7687fa7cfc69430153a0c1dd5cfa9bb7b3f73f7f65 · sha256:27880dba1254afcb… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.