CVE-2026-72574 | picocms Pico up to 2.1.4 Base URL lib/Pico.php Pico::getBaseUrl injection

SecurityVulns

A vulnerability labeled as critical has been found in picocms Pico up to 2.1.4. This vulnerability affects the function Pico::getBaseUrl of the file lib/Pico.php of the component Base URL. The manipulation results in injection.

This vulnerability is known as CVE-2026-72574. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More