Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Caycon- Byteme.Red

#16234of 56,330
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-66600
8.8
2026-07-30
Wolfcms · Wolf Cms · CVE-2026-67206
**Name of the Vulnerable Software and Affected Versions** Wolf CMS versions prior to 0.8.3.2 **Description** An issue in the `FileManagerController` allows authenticated attackers with the `file manager mkfile` capability to achieve remote code execution. This is possible due to missing file extension validation in the `create file()` and `save()` functions, enabling the creation of arbitrary PHP files within the web-accessible `FILES DIR` directory. Execution is triggered by requesting the created file over HTTP. **Recommendations** Update Wolf CMS to version 0.8.3.2 or later. As a temporary mitigation, restrict the `file manager mkfile` capability to trusted users only.
PT-2026-66601
8.8
2026-07-30
Wolfcms · Wolf Cms · CVE-2026-67207
**Name of the Vulnerable Software and Affected Versions** Wolf CMS versions prior to 0.8.3.2 **Description** An authorization bypass exists in the `BackupRestoreController` due to a PHP operator precedence flaw in the permission check expression. This allows authenticated users without administrative privileges to bypass access controls and perform restricted actions, including creating, downloading, and restoring backups. **Recommendations** Update Wolf CMS to version 0.8.3.2 or later.