Arbitrary File Upload Vulnerability in NivoCart by NivoCart
CVE-2026-94104

8.7HIGH

Key Information:

Vendor

Nivocart

Status
Vendor
CVE Published:
20 September 2026

What is CVE-2026-94104?

NivoCart versions up to 2.4.0 are prone to an arbitrary file upload vulnerability found in the File Manager multi() endpoint. This issue arises from inadequate validation of file extensions when uploading new filenames or when the chunks parameter is set to 2 or higher. Attackers with mere view-only access to the back-office can exploit this vulnerability to upload malicious PHP files to the public image/data/ directory, leading to unauthorized remote code execution. This flaw poses grave security risks and requires immediate attention from users and developers.

Affected Version(s)

nivocart 0 <= 2.4.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.