CVE-2026-36467

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leading to remote server access by triggering a reverse shell.

Published 2026-09-21. Last modified 2026-09-22.