CVE WATCH / VULNERABILITY DETAIL
CVE-2026-108101
HIGHCVSS 7.5NVD feed
Published 9 October 2026 · tracked since 10 October 2026
Description
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cro
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-108109 CRITICAL 9.1
- CVE-2026-108107 CRITICAL 9.8
- CVE-2026-108108 HIGH 7.1
- CVE-2026-107806
- CVE-2026-107804 MEDIUM 5.3
- CVE-2026-107805 HIGH 7.5
- CVE-2026-105278 CRITICAL 9.8
- CVE-2026-104081 HIGH 8.1
- CVE-2026-94067 HIGH 8.1
- CVE-2026-94064 HIGH 8.8