CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104081
HIGHCVSS 8.1NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodAr
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8
- CVE-2026-94065 HIGH 8.8
- CVE-2026-100730 CRITICAL 9.8
- CVE-2026-94062 HIGH 8.1
- CVE-2026-62028 MEDIUM 5.4
- CVE-2026-104392 HIGH 8.8