Unopim · Unopim · CVE-2026-82524
**Name of the Vulnerable Software and Affected Versions**
UnoPim versions prior to 2.1.5
**Description**
Authenticated administrators can upload arbitrary PHP files through the TinyMCE image upload endpoint because the system fails to validate file extensions and MIME types. This allows an attacker to upload a PHP web shell to the public storage disk and execute arbitrary operating system commands on the server by accessing the uploaded file via the URL provided in the server response.
**Recommendations**
Update to version 2.1.5 or later.