CVE-2026-82666 | yaojingang GEOFlow up to 2.1.0 Superadmin Theme Editor SiteThemeEditorController.php preview blade code injection (Issue 60)
A vulnerability was found in yaojingang GEOFlow up to 2.1.0. It has been rated as problematic. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin Theme Editor. This manipulation of the argument blade causes code injection.
The identification of this vulnerability is CVE-2026-82666. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More