CVE-2026-49849: 4xmen Xshop
Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code Execution (RCE) on the server, leading to a full system compromise. Version 3.0.4 fixes the issue.
Affected products
- 4xmen Xshop: version 3.0.3 only
Published 2026-08-21. Last modified 2026-09-09.