Arbitrary File Upload Vulnerability in NivoCart by NivoCart
CVE-2026-94104
8.7HIGH
What is CVE-2026-94104?
NivoCart versions up to 2.4.0 are prone to an arbitrary file upload vulnerability found in the File Manager multi() endpoint. This issue arises from inadequate validation of file extensions when uploading new filenames or when the chunks parameter is set to 2 or higher. Attackers with mere view-only access to the back-office can exploit this vulnerability to upload malicious PHP files to the public image/data/ directory, leading to unauthorized remote code execution. This flaw poses grave security risks and requires immediate attention from users and developers.
Affected Version(s)
nivocart 0 <= 2.4.0
