Export limit exceeded: 403697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403697 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 28799 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104069 | 2 Daniel Brendel, Wordpress-extensions | 2 Hortusfox, Hortusfox | 2026-10-09 | 7.2 High |
| HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user. | ||||
Page 1 of 1.