CVE-2026-1445
Last modified
CVE-2026-1445 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability affects unknown code of the file controllers/books_center/upload_bookCover.php. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability affects unknown code of the file controllers/books_center/upload_bookCover.php. Performing a manipulation of the argument book_cover results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1445?
How severe is CVE-2026-1445?
How do I fix CVE-2026-1445?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14442An information exposure vulnerability in the job scheduling …6.9
- CVE-2026-14443Incomplete log sanitization during bulk IPsec policy collect…8.4
- CVE-2026-14444The WP Fusion (Pro) plugin for WordPress is vulnerable to Pr…7.5
- CVE-2026-14446IBM WebSphere Application Server 9.0, and 8.5 is vulnerable …9.8
- CVE-2026-14448An high privileged remote attacker can exploit an authentica…8.6
- CVE-2026-14449u5CMS through v12.8.8 is vulnerable to reflected XSS via the…6.4
- CVE-2026-14450A flaw was found in the MaaS API. This vulnerability allows …9.9
- CVE-2026-14453This vulnerability is a critical Server-Side Template Inject…9.6
- CVE-2026-14454Imager versions before 1.033 for Perl treat unsigned EXIF IF…9.8
- CVE-2026-14456Issue summary: When an OpenSSL QUIC server (Listener SSL obj…7.5
- CVE-2026-14457Issue summary: In a server or client configuration with RFC7…7.5
- CVE-2026-14459Improper neutralization of argument delimiters in a command …8.8
Are you affected by CVE-2026-1445?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
