DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.852
EPSS Ranking 99.3%