CVE-2026-4509
MEDIUMPbootCMS File Upload file.php incomplete blacklist
Title source: cnaDescription
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
References (4)
Scores
CVSS v3
6.3
EPSS
0.0006
EPSS Percentile
19.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-183
CWE-184
Status
published
Products (13)
n/a/PbootCMS
3.2.0
n/a/PbootCMS
3.2.1
n/a/PbootCMS
3.2.10
n/a/PbootCMS
3.2.11
n/a/PbootCMS
3.2.12
n/a/PbootCMS
3.2.2
n/a/PbootCMS
3.2.3
n/a/PbootCMS
3.2.4
n/a/PbootCMS
3.2.5
n/a/PbootCMS
3.2.6
... and 3 more
Published
Mar 21, 2026
Tracked Since
Mar 21, 2026