Remote Code Execution Vulnerability in Neethuharii CafeManagement Plugin
CVE-2026-96513

6.9MEDIUM

Key Information:

Vendor
CVE Published:
23 September 2026

What is CVE-2026-96513?

A significant security vulnerability has been identified in the Neethuharii CafeManagement application, specifically within the AddProductCode.php file. This flaw allows an attacker to perform an unrestricted file upload by manipulating the image argument, potentially leading to remote code execution. The vulnerability can be exploited remotely, making it crucial for users to take immediate action to mitigate the risk. Despite the vendor being informed of this issue, no response has been received, and the details regarding affected product updates have not been disclosed due to the rolling release system employed by the vendor.

Affected Version(s)

CafeManagement 5f743043a9a04f903678697f061d2e220e544c09

CafeManagement 66c837020e25af4866cb69b23ec3af4e0e1510c9

CafeManagement f80fe4442d5e15af5c78df3f22177a131c1e6f32

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yashkumar Keral (VulDB User)
VulDB CNA Team
.