← Back to search

CVE-2026-94104

8.8 HIGHpublic exploit available

Published 2026-09-20 · Updated 2026-09-24

AI risk analysis

Summary
NivoCart through 2.4.0 allows attackers with view-only back-office access to upload PHP files, leading to remote code execution.
Exploitability
Exploitation is moderately difficult as it requires view-only back-office access and knowledge of the File Manager multi() endpoint. Attackers must also upload a PHP file to the image/data/ directory.
Blast radius
If exploited, this vulnerability could lead to full control over the affected system, including data theft, data manipulation, and unauthorized actions.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to NivoCart 2.4.1 or later.
rcewebuploadphp

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-office access can upload PHP files to the web-accessible image/data/ directory and execute them for remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.