CVE-2026-53599
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/
CVSS
7.5
Alto
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 31 jul 2026 · Última mod.: 9 sept 2026 · CWE-434
0.3%EPSS · 30 días0.4%
2026-08-242026-09-22
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.
- github.comhttps://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340
- github.comhttps://github.com/redaxo/core/pull/6538
- github.comhttps://github.com/redaxo/core/releases/tag/5.21.1
- github.comhttps://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25
- github.comhttps://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-955007.3 ALT—
——0A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.5hCVE-2026-954997.3 ALT—
——0A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.5hCVE-2026-887388.8 ALT15.6%
——5Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file is stored in a web-accessible executable location and can be accessed directly over HTTP without authentication, resulting in remote code execution.4hCVE-2026-887456.1 MED3.5%
——1EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.8hCVE-2026-52835—41.6%
——12Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.filename or database_file.filename directly to CACHE_DIR without basename reduction or a containment check. An administrator or caller with the instance API key can submit a multipart filename containing parent-directory segments, causing the upload to be created or overwritten outside CACHE_DIR before file-content validation runs. The write is limited to paths permitted to the Tautulli process, but it can enable configuration tampering, service disruption, or code execution. This issue is fixed in version 2.17.2.1dCVE-2026-364677.2 ALT43.9%
——13Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.1d