CVE-2026-84063

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.

Scoring

Severity
HIGH
CVSS base score
8.5
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.43%
CWE
CWE-434
Published
2026-09-10
Last modified
2026-09-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs