PatchSiren

vincent-peugnet CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vincent-peugnet CVE published 2026-10-04

CVE-2026-105124

A stored cross-site scripting vulnerability exists in W (vincent-peugnet/wcms) through 3.18.0, allowing unauthenticated attackers to inject scripts via the login user field and visitor comment website field. This vulnerability can lead to potential script execution with administrator or editor privileges, and defenders should assess exposure and prioritize verification and remediation efforts accordingly. [truncated]

HIGH vincent-peugnet CVE published 2026-10-04

CVE-2026-105123

A remote code execution vulnerability exists in W (vincent-peugnet/wcms) through version 3.18.0. Authenticated editors can write arbitrary files by exploiting the unvalidated path in the POST /api/v0/media/upload/[*:path] endpoint. This allows attackers to upload .php files that can be executed by the web server. Additionally, attackers can use encoded ../ sequences to write outside the media directory an [truncated]