CVE-2023-53869
WEBIGniter 28.7.23 - RCE
Title source: llmDescription
WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.
Exploits (1)
Scores
EPSS
0.0035
EPSS Percentile
57.2%
Classification
CWE
CWE-434
Status
draft
Timeline
Published
Dec 15, 2025
Tracked Since
Feb 18, 2026