PatchSiren

unopim CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH unopim CVE published 2026-09-02

CVE-2026-82524

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T20:17:39.210Z and has not been modified since then. UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. This [truncated]