CVE-2026-15518Medium· 4.7▾ SunlitA vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
0.2% → 0.4%
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument qqfilename leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13815Medium· 6.3A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2
CVE-2026-19383Medium· 4.7A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1
CVE-2026-1609High· 8.1A flaw was found in Keycloak
CVE-2026-16226Medium· 4.7A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0
CVE-2026-50006Critical· 9.1Anyquery is an SQL query engine built on top of SQLite
CVE-2026-15539Medium· 4.7A security vulnerability has been detected in SourceCodester Online Book Store System 1.0