CVE-2026-56124 HIGH

CVE-2026-56124: phpUploader < 2.0.2 Unauthenticated Database Exposure via index model

Vendor Shimosyan
Product phpUploader
Weakness CWE-359
Published June 29, 2026
Last update June 29, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

Key dates

02Disclosure timeline

June 29, 2026 CVE published
June 29, 2026 Record updated