CVE-2022-50806
HIGH4images 1.9 - Authenticated RCE
Title source: llmDescription
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.
Exploits (1)
Scores
CVSS v3
7.2
EPSS
0.0045
EPSS Percentile
63.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
4homepages/4images
1.9
4Homepages/4images
1.9
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026