PT-2026-95955 · Nivocart · Nivocart

·

CVE-2026-94104

·

Published

2026-09-20

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NivoCart versions prior to 2.4.1
Description An arbitrary file upload flaw exists in the File Manager multi() endpoint. The system fails to validate file extensions for new filenames or when the chunks parameter is set to 2 or higher. This allows users with view-only back-office access to upload PHP files to the web-accessible image/data/ directory, which can lead to remote code execution.
Recommendations Update NivoCart to a version newer than 2.4.0. Restrict access to the multi() endpoint in the File Manager to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94104

Affected Products

Nivocart