PatchSiren

light0011 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM light0011 CVE published 2026-09-07

CVE-2026-86308

A vulnerability was detected in light0011 cms, affecting an unknown processing of the file App/Common/Conf/config.php in Debug Mode. The manipulation of the argument DB_DEBUG results in information disclosure, and remote attacks are possible. The exploit is now public. The product uses rolling releases, so version details for affected and updated releases are not available.

MEDIUM light0011 CVE published 2026-09-07

CVE-2026-86306

A weakness in light0011 cms allows for improper authentication through manipulation of the Username argument in the Cookie Helper component. This issue, publicly disclosed, may allow remote attacks. The product uses a rolling release system, so affected or updated versions are not specified. The project was informed but has not yet responded. Defenders should verify exposure, monitor for anomalies, and pr [truncated]

MEDIUM light0011 CVE published 2026-09-07

CVE-2026-86305

A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. The vulnerability affects the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php, allowing for unrestricted upload. The attack can be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopt [truncated]