HIGH
unopim
CVE published 2026-09-02
CVE-2026-82524
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T20:17:39.210Z and has not been modified since then. UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. This [truncated]