CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105123
HIGHCVSS 8.8NVD feed
Published 4 October 2026 · tracked since 4 October 2026
Description
W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequenc
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105124 MEDIUM 6.1
- CVE-2026-105125 LOW 3.7
- CVE-2026-105118 MEDIUM 4.7
- CVE-2026-97873
- CVE-2026-71889
- CVE-2026-71891
- CVE-2026-71885
- CVE-2026-71886
- CVE-2026-92767 MEDIUM 6.4
- CVE-2026-92084 CRITICAL 9.1