---
id: CVE-2026-84063
title: >-
  BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of
  file with dangerous type
summary: >-
  BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of
  file with dangerous type. If this vulnerability is exploited, an arbitrary
  file may be uploaded by an attacker who can log in to the product, potentially
  allo…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-434
vendor: 'D-ZERO CO.,LTD.'
product: BurgerEditor
affected:
  - BurgerEditor 3.2.0 through 3.4.0
  - BurgerEditor 2.28.0 through 2.30.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T17:39:46.164484Z'
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:41:24.347Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-84063'
references:
  - url: 'https://jvn.jp/en/jp/JVN21088484/'
  - url: 'https://burger.d-zero.co.jp/blogs/archives/3'
tags:
  - cve.org
epss: 0.00435
epssPercentile: 0.3504
ingestedAt: '2026-09-11T14:42:19.866Z'
---

## Overview

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.

## Affected

- `BurgerEditor 3.2.0 through 3.4.0`
- `BurgerEditor 2.28.0 through 2.30.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
