CVE-2022-50806

HIGH

4images 1.9 - Authenticated RCE

Title source: llm

Description

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

Exploits (1)

exploitdb WORKING POC
by Andrey Stoykov · textwebappsphp
https://www.exploit-db.com/exploits/51147

Scores

CVSS v3 7.2
EPSS 0.0045
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
4homepages/4images 1.9
4Homepages/4images 1.9
Published Jan 13, 2026
Tracked Since Feb 18, 2026