CVE-2026-56124
shimosyan phpUploader
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.
- CVSS
- 8.7
- EPSS
- 0.36% 28.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.30