CVE-2026-91849 | WuzhiCMS up to 4.1.0 Avatar Upload index.php?m=member&f=user&v=setAvatar member::setAvatar File unrestricted upload (Issue 219)

SecurityVulns

A vulnerability categorized as critical has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload.

This vulnerability is identified as CVE-2026-91849. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More