CVE-2026-104069

CVE-2026-104069 published: HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authe...

View full NVD advisory → ← Back to CVE watch