HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-105123 — W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnera...

·Source: NIST NVD

Updated:

Executive Summary

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path

Analysis

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST /api/v0/media/upload/[*:path]. Attackers can upload .php files executed by the web server, use encoded ../ sequences to write outside the media directory, and delete arbitrary files via DELETE /api/v0/media/[*:path]. CVSS Score: 8.8. Published: 2026-10-04T00:16:35.703.

Indicators of Compromise (1)

CVE (1)
CVE-2026-105123
Source Attribution

Originally published by NIST NVD on Oct 4, 2026. Verified by: NIST.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-105126 — LaraDashboard before 1.4.8 contains an improper privilege management vulnerabili...

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade and module installation functions for code execution.

CVE-2026-105126
NIST NVD
LOWVulnerability

The Italian Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach

The following is a machine translation of a press release by Italy’s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a... Source

DataBreaches.net
LOWVulnerability

Italy’s Data Protection Authority fines IQVIA €7 million over data protection breach

The following is a machine translation of a press release by Italy’s privacy guarantor: Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a... Source

DataBreaches.net