PatchSiren

wolfcms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wolfcms CVE published 2026-07-30

CVE-2026-67206

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:18:14.030Z and has not been modified since then. The NVD entry is currently Deferred. Wolf CMS 0.8.3.1 has a remote code execution vulnerability in FileManagerController due to missing file extension validation in create_file() and save() functions, allowing authenticated attackers with file_m [truncated]