CVE-2025-26260: Plenti
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.
Affected products
- Plenti Plenti: before 0.7.17 (fixed in 0.7.17)
Published 2025-03-12. Last modified 2026-06-17.