CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)
A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-90710. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More