CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93352

CRITICALCVSS 9.8NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-93352 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93352

CRITICALCVSS 9.8NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via t

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]