---
id: CVE-2026-49849
title: xShop is an open-source shop developed in Laravel
summary: >-
  xShop is an open-source shop developed in Laravel. An Unrestricted File Upload
  vulnerability in xShop version 3.0.3 allows an authenticated administrator to
  upload executable files (e.g., .php). By uploading a specially crafted php
  file,…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2026-08-21'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:06:39.057'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49849'
references:
  - url: >-
      https://github.com/4xmen/xshop/commit/dd4a3add9d6f5b5f9dde9685e97f51057903a1db
    label: security-advisories@github.com
  - url: 'https://github.com/4xmen/xshop/pull/64'
    label: security-advisories@github.com
  - url: 'https://github.com/4xmen/xshop/releases/tag/v3.0.4'
    label: security-advisories@github.com
  - url: 'https://github.com/4xmen/xshop/security/advisories/GHSA-fc35-qjg3-f6g7'
    label: security-advisories@github.com
  - url: 'https://github.com/4xmen/xshop/security/advisories/GHSA-fc35-qjg3-f6g7'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00992
epssPercentile: 0.60945
ingestedAt: '2026-09-09T21:22:45.547Z'
---

## Overview

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
