HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105123 — W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnera...

·Source: NIST NVD

Updated:

Executive Summary

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path

Analysis

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. CVSS Score: 8.8. Published: 2026-10-04T00:16:35.703.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105123
Source Attribution

Originally published by NIST NVD on Oct 4, 2026. Verified by: NIST.

Related Threats