CVE-2026-92247
synaptikcms synaptik-cms Admin File Manager file-manager.php rename unrestricted upload
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.
| CWE | CWE-434 CWE-284 |
| Vendor | synaptikcms |
| Product | synaptik-cms |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for synaptikcms synaptik-cms
Be the first to know when new medium vulnerabilities affecting synaptikcms synaptik-cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
synaptikcms / synaptik-cms
1.3.4.0 1.3.4.1 1.3.4.2 1.3.4.3 1.3.4.4
References
vuldb.com: https://vuldb.com/vuln/404682 vuldb.com: https://vuldb.com/vuln/404682/cti vuldb.com: https://vuldb.com/cve/CVE-2026-92247 vuldb.com: https://vuldb.com/submit/934183 github.com: https://github.com/d1n3sh-0x3/synaptikcms-security-research github.com: https://github.com/synaptikcms/synaptik-cms/releases/tag/v1.3.5
Credits
๐ Dinesh_goud (VulDB User)