OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-95499

HIGH · CVSS 7.3 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability in the php-file-manager-with-code-editor allows for unrestricted file uploads through manipulation of the `move_uploaded_file` function in filemanager.php. This flaw can be exploited remotely, potentially enabling attackers to upload malicious files to the server. Organizations using this software should prioritize patching or mitigating this vulnerability to prevent unauthorized access and potential system compromise.

CVE
CVE-2026-95499
Severity
HIGH
CVSS
7.3
EPSS
0.47%

Original NVD Description

A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.