← Back to CVE List
Vulnerability Intelligence Report
HortusFox < 6.2 Remote Code Execution via Theme Import

CVE-2026-104069

x_open-source

HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-434 ↗Unrestricted Upload of File with Dangerous Type

Affected Products & Versions

Vendor Product Affected Versions
danielbrendel hortusfox-web 0 < 6.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-10-01T18:02:50
Published2026-10-06T14:55:07
Patch Date2026-10-03
Last Updated2026-10-06T16:09:16

LINK COPIED TO CLIPBOARD