CVE-2024-35324: Douchat

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.

Affected products

  • Douchat Douchat: version 4.0.5 only

Published 2024-05-28. Last modified 2026-06-17.