๐Ÿ” CVE Alert

CVE-2026-56124

HIGH 7.5

phpUploader < 2.0.2 Unauthenticated Database Exposure via index model

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

CWE CWE-359 CWE-497
Vendor shimosyan
Product phpuploader
Published Jun 29, 2026
Last Updated Jun 29, 2026
Stay Ahead of the Next One

Get instant alerts for shimosyan phpuploader

Be the first to know when new high vulnerabilities affecting shimosyan phpuploader are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

shimosyan / phpUploader
0 < 2.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/shimosyan/phpUploader/releases/tag/v2.0.2 github.com: https://github.com/shimosyan/phpUploader/pull/294 github.com: https://github.com/shimosyan/phpUploader/commit/45dc4f1c9a2de5ade427deebad0148834c0e8c50 vulncheck.com: https://www.vulncheck.com/advisories/phpuploader-unauthenticated-database-exposure-via-index-model

Credits

@rayyb0t (https://github.com/rayyb0t) VulnCheck