CVE-2026-40548
Unrestricted Upload of File with Dangerous Type in SOPlanning
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
12th
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server. When combined with CVE-2026-40547 (Path Traversal), the malicious file (e.g., a PHP script) can be placed in a web-accessible location and executed via the browser. This issue affects SOPlanning version 1.55 and below.
| CWE | CWE-434 |
| Vendor | soplanning |
| Product | soplanning |
| Published | Jun 1, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for soplanning soplanning
Be the first to know when new unknown vulnerabilities affecting soplanning soplanning are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
SOPlanning / SOPlanning
0 ≤ 1.55
References
Credits
Łukasz Jaworski