CVE-2026-36722
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.
Published 2026-06-09. Last modified 2026-07-23.