CVE-2023-53869

WEBIGniter 28.7.23 - RCE

Title source: llm

Description

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textwebappsphp
https://www.exploit-db.com/exploits/51736

Scores

EPSS 0.0035
EPSS Percentile 57.2%

Classification

CWE
CWE-434
Status draft

Timeline

Published Dec 15, 2025
Tracked Since Feb 18, 2026