CVE-2025-26260: Plenti

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

Affected products

  • Plenti Plenti: before 0.7.17 (fixed in 0.7.17)

Published 2025-03-12. Last modified 2026-06-17.