CVE-2026-91849

Source
https://cve.org/CVERecord?id=CVE-2026-91849
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91849.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91849
Published
2026-09-15T15:30:07Z
Modified
2026-09-19T03:31:01Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
WuzhiCMS Avatar Upload index.php setAvatar unrestricted upload
Details

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-284",
        "CWE-434"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91849.json"
}
References

Affected packages

Git / github.com/wuzhicms/wuzhicms

Affected ranges

Type
GIT
Repo
https://github.com/wuzhicms/wuzhicms
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0"
        },
        {
            "last_affected": "4.0"
        },
        {
            "introduced": "4.1.0"
        },
        {
            "last_affected": "4.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

4.*
4.0
4.1.0
v4.*
v4.0.0
v4.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91849.json"