CVE-2026-56124: Shimosyan Phpuploader

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

Affected products

  • Shimosyan Phpuploader: before 2.0.2 (fixed in 2.0.2)

Published 2026-06-29. Last modified 2026-07-14.