CVE-2026-105123

Summary

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[:path].

Affected Software

VendorProductVersion RangeStatus
vincent-peugnetwcms0 <= 3.18.0affected

Weaknesses

  • CWE-434: Unrestricted Upload of File with Dangerous Type

References