CVE-2026-18959 | yushine InnoShop up to 0.8.2 Files Endpoint panel-api.php destroyFiles path traversal

SecurityVulns

A vulnerability, which was classified as critical, has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal.

This vulnerability appears as CVE-2026-18959. The attack may be initiated remotely. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More