CVE-2026-2113
HIGHyuan1994 tpadmin <1.3.12 - Deserialization
Title source: llmDescription
A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Exploits (2)
github
WORKING POC
10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-2113
References (4)
Scores
CVSS v3
7.3
EPSS
0.0001
EPSS Percentile
2.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
CWE-20
CWE-434
Status
published
Affected Products (1)
tpadmin_project/tpadmin
< 1.3.12
Timeline
Published
Feb 07, 2026
Tracked Since
Feb 18, 2026