PT-2026-66600 · Wolfcms · Wolf Cms

·

CVE-2026-67206

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create file() and save() functions. Attackers with the file manager mkfile capability can write malicious PHP content into the web-accessible FILES DIR directory and trigger execution by requesting the file over HTTP.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67206

Affected Products

Wolf Cms