Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. This patch is called 05b4f9efeb79e9d72a693232334d7529687f896f. It is best practice to apply a patch to resolve this issue. | |
| Title | SveltyCMS File Upload Endpoint upload-media server-side request forgery | |
| First Time appeared |
Sveltycms
Sveltycms sveltycms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:sveltycms:sveltycms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sveltycms
Sveltycms sveltycms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T14:45:14.943Z
Reserved: 2026-09-18T08:26:52.415Z
Link: CVE-2026-93506
No data.
Status : Deferred
Published: 2026-09-18T15:17:19.410
Modified: 2026-09-18T19:14:56.310
Link: CVE-2026-93506
No data.
OpenCVE Enrichment
No data.
