HIGH
danielbrendel
CVE published 2026-09-17
CVE-2026-92980
CVE-2026-92980 is a remote code execution vulnerability in HortusFox-Web versions prior to 6.1. Authenticated administrators can exploit the Import/Export feature to execute arbitrary OS commands as the web server user. This vulnerability allows attackers to leverage the Import/Export functionality, intended solely for data portability, to deploy and execute malicious code on the underlying application se [truncated]