A vulnerability marked as critical has been reported in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is known as CVE-2026-7508. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The code repository of the project has not been active for many years.