CVE-2026-95499 | JosephChuks php-file-manager-with-code-editor up to 3.0 filemanager.php move_uploaded_file files unrestricted upload
A vulnerability categorized as critical has been discovered in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload.
This vulnerability is handled as CVE-2026-95499. The attack can be executed remotely. There is not any exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More