Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code. | |
| Title | HortusFox through 6.3 Unrestricted File Upload via Plant Attachments | |
| First Time appeared |
Hortusfox
Hortusfox hortusfox |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:hortusfox:hortusfox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hortusfox
Hortusfox hortusfox |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T14:08:08.807Z
Reserved: 2026-10-09T13:43:07.777Z
Link: CVE-2026-108101
No data.
Status : Deferred
Published: 2026-10-09T15:17:10.667
Modified: 2026-10-09T15:17:10.800
Link: CVE-2026-108101
No data.
OpenCVE Enrichment
No data.
-
CWE-434
Unrestricted Upload of File with Dangerous Type