CVE-2026-86240 | liufee FeehiCMS up to 2.1.1 UEditor Uploader.php catchImage source[] server-side request forgery (Issue 95)
A vulnerability was found in liufee FeehiCMS up to 2.1.1 and classified as problematic. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery.
This vulnerability is identified as CVE-2026-86240. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More