CVE-2026-31843
goodoneuz pay-uz
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.
- CVSS
- 10
- EPSS
- 2.76% 84.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.16