Junglewise Threat Intelligence

CVE-2026-95499: JosephChuks php-file-manager-with-code-editor unrestricted upload in filemanager.php

CVE-2026-95499 · Severity: high · CVSS 7.3 · Published 2026-09-22

Executive brief

php-file-manager-with-code-editor is a web-based file manager and code editor. A flaw in the file upload functionality allows attackers to upload arbitrary files to the server without proper validation, potentially leading to remote code execution or data compromise. No vendor response has been received regarding this issue.

Technical details

An unrestricted file upload vulnerability exists in the move_uploaded_file function of filemanager.php, where the files argument can be manipulated to bypass upload restrictions. The vulnerability is remotely exploitable and does not require authentication. Successful exploitation allows an attacker to upload and execute malicious files on the server.

Affected products

  • JosephChuks php-file-manager-with-code-editor up to 3.0

Timeline

  • 2026-09-22: disclosed

References

Related threats