CVE-2026-91849 | WuzhiCMS up to 4.1.0 Avatar Upload index.php?m=member&f=user&v=setAvatar member::setAvatar File unrestricted upload (Issue 219)
A vulnerability categorized as critical has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload.
This vulnerability is identified as CVE-2026-91849. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More