Remote Code Execution Vulnerability in W CMS by Vincent Peugnet
CVE-2026-105123
8.7HIGH
What is CVE-2026-105123?
W CMS by Vincent Peugnet, up to version 3.18.0, has a significant vulnerability that allows authenticated editors to exploit the media upload API. By manipulating the unvalidated file paths in POST requests, attackers can upload malicious .php files that can be executed by the web server. This vulnerability can also be leveraged to write files outside of the designated media directory using encoded ../ sequences, and, through DELETE requests, to remove arbitrary files from the server. This poses a serious risk to the integrity and security of the application.
Affected Version(s)
wcms 0 <= 3.18.0
