Security Advisory - Published 2026-06-27 - PHP / CMS

PHP CMS batch: check Cacti, GeoVision, Pagekit, HTMLy, Genshi, and small PHP apps

This group covers PHP-facing apps and adjacent template or monitoring stacks. Treat it as an exposure review: public panels, old CMS builds, graph/report pages, file movement, uploaded files, and database query errors.

Defensive scope: check systems you own or are approved to repair. This page keeps to version checks, exposure review, logs, patching, and compromise indicators. It stays on inventory, patching, log review, and compromise triage.

Affected CVEs in this batch

CVEProductAffectedReviewCVSS
CVE-2026-0685Genshi Template Enginevendor-fixed releaseweb and app logs9.8
CVE-2026-57878GeoVisionvendor-fixed releaseweb and app logs9.8
CVE-2026-57879GeoVisionvendor-fixed releaseweb and app logs9.8
CVE-2026-57880GeoVisionvendor-fixed releaseweb and app logs9.8
CVE-2026-57881GeoVisionvendor-fixed releaseweb and app logs9.8
CVE-2026-57518Pagekit CMSvendor-fixed releaseweb and app logs8.8
CVE-2026-57877GeoVisionvendor-fixed releaseweb and app logs8.6
CVE-2026-45233HTMLy CMSthrough 3.1.1web and app logs8.1
CVE-2026-37149Grocery Store Management Systemvendor-fixed releaseweb and app logs7.7
CVE-2026-57872GeoVisionvendor-fixed releaseweb and app logs7.5
CVE-2026-57873GeoVisionvendor-fixed releaseweb and app logs7.5
CVE-2026-57874GeoVisionvendor-fixed releaseweb and app logs7.5
CVE-2026-57875GeoVisionvendor-fixed releaseweb and app logs7.5
CVE-2026-57876GeoVisionvendor-fixed releaseweb and app logs7.5
CVE-2026-40083Cactivendor-fixed releaseCacti and web logs7.2
CVE-2026-40084Cactivendor-fixed releaseCacti and web logs6.5
CVE-2026-40080Cactivendor-fixed releaseCacti and web logs6.1
CVE-2026-39900Cactivendor-fixed releaseCacti and web logs6.1

What to check

  • Cacti 1.2.30 and earlier, especially manager, report, auth profile, graph, and package import areas.
  • GeoVision appliance or web components listed by the vendor advisory.
  • Pagekit CMS 1.0.18 user-management permissions and administrator role changes.
  • HTMLy CMS through 3.1.1 file movement, media paths, and low-privilege user activity.
  • Genshi template engine 0.7.9 use in services that evaluate template expressions.
  • Small PHP/MySQL apps exposed to the internet, especially grocery/store demo systems and phpMyAdmin-backed deployments.

Safe fix path

  1. Patch or remove the affected PHP application before attempting cleanup.
  2. Preserve web logs, application logs, database errors, and recent file timestamps.
  3. Review created users, changed roles, uploads, report output files, and unexpected redirects.
  4. Move unsupported demo or abandoned PHP apps behind authentication or remove them from public hosting.

Compromise indicators

  • New users, role changes, unexpected sessions, or unknown API tokens.
  • Files changed during the exposure window, especially executable files or generated configs.
  • Repeated application errors, database errors, queue failures, or unusual outbound requests.
  • Plugin, container, service, or package versions that differ from the expected deployment record.

When to ask Ping7 for repair

Use Ping7 CVE Repair when the affected component is public, logs show suspicious activity, patching may break production, or cleanup requires file, database, user, token, or container review.

References