CVE-2026-67206
published 2026-07-30CVE-2026-67206: Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
1.40%
70.7th percentile
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger execution by requesting the file over HTTP.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wolfcms | wolfcms | <= 0.8.3.1 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension
ghsa_unreviewed·2026-07-30
CVE-2026-67206 [HIGH] CWE-434 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger execution by requesting the file over HTTP.
VulDB
Wolf CMS up to 0.8.3.1 FileManagerController create_file/save input validation
vuldb·2026-07-30·CVSS 8.8
CVE-2026-67206 [HIGH] Wolf CMS up to 0.8.3.1 FileManagerController create_file/save input validation
A vulnerability has been found in Wolf CMS up to 0.8.3.1 and classified as problematic. The impacted element is the function create_file/save of the component FileManagerController. This manipulation causes improper input validation. This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2026-67206. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No writeups or analysis indexed.
2026-07-30
Published