CVE-2024-24393: Oaooa Pichome

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

Affected products

  • Oaooa Pichome: version 1.1.01 only

Published 2024-02-08. Last modified 2026-06-17.