CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104890
HIGHCVSS 7.2NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An aut
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog