CVE-2026-102366
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept
CVSS
4.4
Medio
EPSS
0.2%
p5
KEV
—
Exploit Today
1
0-100
Publicado: 29 sept 2026 · Última mod.: 29 sept 2026 · CWE-434
Sin historial EPSS suficiente todavía.
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.
- github.comhttps://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A03_admin_file_upload_xss.py
- github.comhttps://github.com/gz-yami/mall4j
- github.comhttps://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-admin/src/main/java/com/yami/shop/admin/controller/FileController.java#L44-L64
- github.comhttps://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/java/com/yami/shop/service/impl/AttachFileServiceImpl.java#L62-L81
- www.vulncheck.comhttps://www.vulncheck.com/advisories/mall4j-through-4.0-unrestricted-file-upload-in-admin-file-endpoints
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1024547.2 ALT—
———EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.13hCVE-2026-1028426.3 MED—
——0A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the argument ADMIN_RS_KCFINDER leads to unrestricted upload. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.8hCVE-2026-703569.1 CRÍ—
——0The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.1dCVE-2026-96431—17.9%
——5Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version
before 2023/03/24 allows remote authenticated users to execute arbitrary
system commands via a malicious file.1dCVE-2026-1022634.7 MED11.0%
——3A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-54675—46.5%
——14FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leading directly to remote code execution (RCE). Authentication with a known username is required. The vulnerability stems from insufficient path sanitization in the file conversion process, enabling path traversal attacks that place malicious PHP files in the web server's root directory. This issue has been patched in versions 16.0.10 and 17.0.5.2d