CVE-2026-39292
Last modified
CVE-2026-39292 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-39292?
How severe is CVE-2026-39292?
How do I fix CVE-2026-39292?
Are you affected by CVE-2026-39292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
