CVE-2026-4509
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.29%
- CWE
- CWE-184, CWE-183
- Published
- 2026-03-21
- Last modified
- 2026-03-24
Affected products
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
- n/a PbootCMS
Weakness type
Related vulnerabilities
- CVE-2026-87911 — Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server
- CVE-2026-85788 — Incomplete list of disallowed inputs in awslabs mysql-mcp-server
- CVE-2026-86199 — PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
- CVE-2026-79696 — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
- CVE-2026-82536 — Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
- CVE-2026-69624 — Active Directory Certificate Services (AD CS) Tampering Vulnerability
- CVE-2026-70334 — Visual Studio Code Security Feature Bypass Vulnerability
- CVE-2026-33197 — BDS Module Bypass Secure Boot Advisory