SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57795

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in themelexus Kitchor allows for local file inclusion due to improper control of filenames in PHP include/require statements, potentially enabling attackers to execute arbitrary code on the server. This high-severity flaw affects versions up to and including 1.4.3, making it critical for users of Kitchor to prioritize immediate patching or mitigation measures to prevent exploitation. Organizations utilizing this software should assess their exposure and take action to secure their systems against potential attacks.

CVE
CVE-2026-57795
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.