CVE-2026-108101

CVE-2026-108101 published: HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files...

View full NVD advisory → ← Back to CVE watch