← Terug naar overzicht

A security flaw has been identified in the light0011 CMS project affecting the Upload::upload function within ThinkPHP/Library/Think/Upload.class.php. The vulnerability allows unrestricted file uploads, which can be exploited remotely. A public exploit has already been released, increasing the risk of active exploitation. The affected software uses a rolling release strategy, making it impossible to specify exact affected or patched version numbers. The vendor was notified via a GitHub issue report but has not responded or issued a fix. The vulnerability is tracked as CVE-2026-86305 and is indexed on both NVD and VulDB. Due to the public availability of exploit code and lack of vendor response, the risk remains high for users of this CMS.

Affected products

  • ThinkPHP
  • light0011 CMS

Related CVE's

  • CVE-2026-86305

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities