Junglewise Threat Intelligence

CVE-2026-49849: xShop unrestricted file upload vulnerability

CVE-2026-49849 · Severity: critical · CVSS 9.1 · Published 2026-08-21

Executive brief

xShop is an open-source e-commerce platform built with Laravel that allows store administrators to manage products and configurations. A file upload validation flaw in version 3.0.3 permits authenticated admins to upload executable files (such as PHP scripts), which can be used to execute arbitrary code on the web server. This leads to complete server compromise and enables attackers to steal customer data, modify business operations, or use the server for further attacks.

Technical details

The vulnerability is an unrestricted file upload flaw in xShop 3.0.3 that fails to properly validate uploaded file types. An authenticated administrator can upload PHP executable files to the application, bypassing file type restrictions. Upon upload, the attacker can access the file through the web server and execute arbitrary PHP code, achieving Remote Code Execution (RCE) with the privileges of the web server process. The vulnerability requires administrative authentication, but once exploited, grants full server access. Version 3.0.4 addresses this issue by implementing proper file type validation.

Affected products

  • xShop xShop 3.0.3

Timeline

  • 2026-08-21: disclosed
  • 2026-02-14: patched: Version 3.0.4 released with fix

References