Below are listed all the CVEs I have discovered and reported.

CRIT
9.8
CVSS
3.1
CVE-2026-30993 CODE INJECTION
Slah Informática CMS - All Versions Through 1.5.0 (Remote Code Execution) · January 15, 2026

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

Note: certain CVEs are still in the verification process due to MITRE's response time or the vendor's 90-day responsible disclosure period.

This list is constantly updated.