CVE-2026-94104
8.8 HIGHpublic exploit availablePublished 2026-09-20 · Updated 2026-09-24
AI risk analysis
- Summary
- NivoCart through 2.4.0 allows attackers with view-only back-office access to upload PHP files, leading to remote code execution.
- Exploitability
- Exploitation is moderately difficult as it requires view-only back-office access and knowledge of the File Manager multi() endpoint. Attackers must also upload a PHP file to the image/data/ directory.
- Blast radius
- If exploited, this vulnerability could lead to full control over the affected system, including data theft, data manipulation, and unauthorized actions.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to NivoCart 2.4.1 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Public exploit & PoC references
- https://github.com/nivocart/nivocart
- https://github.com/nivocart/nivocart/blob/6ea6600cda1263ae70c0aab0a70d31091a32c46b/upload/admin/controller/common/filemanager.php#L527-L562
- https://github.com/nivocart/nivocart/blob/6ea6600cda1263ae70c0aab0a70d31091a32c46b/upload/admin/controller/common/filemanager_full.php
- https://github.com/nivocart/nivocart/issues/25
All references
- https://github.com/nivocart/nivocart
- https://github.com/nivocart/nivocart/blob/6ea6600cda1263ae70c0aab0a70d31091a32c46b/upload/admin/controller/common/filemanager.php#L527-L562
- https://github.com/nivocart/nivocart/blob/6ea6600cda1263ae70c0aab0a70d31091a32c46b/upload/admin/controller/common/filemanager_full.php
- https://github.com/nivocart/nivocart/issues/25
- https://www.vulncheck.com/advisories/nivocart-through-2.4.0-arbitrary-file-upload-rce-via-filemanager
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-70356PoC
- CRITICALCVE-2026-82187
- CRITICALCVE-2026-93352PoC
- HIGHCVE-2026-12264
- CRITICALCVE-2026-14175
- HIGHCVE-2026-14553
- CRITICALCVE-2026-16618
- CRITICALCVE-2026-18143
Related by shared AI tags and CWE weakness class. Browse the full archive.