What is CVE-2026-18788?
This is a critical security flaw in Trippo ResponsiveFilemanager up to version 9.14.0, involving an unrestricted file upload vulnerability in the `filemanager/dialog.php` file. A remote attacker can exploit this to upload arbitrary files. Immediate update to the latest version is strongly recommended.
Azərbaycanca: Bu, Trippo ResponsiveFilemanager-in 9.14.0-a qədər olan versiyalarında `filemanager/dialog.php` faylındakı məchul funksiyada aşkar edilmiş ciddi təhlükəsizlik boşluğudur. Uzaqdan hücum edən şəxs fayl yükləmə məhdudiyyətlərini keçərək özbaşına fayl yükləyə bilər. Dərhal tətbiqi son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which product is affected by CVE-2026-18788?
CVE-2026-18788 affects the Trippo ResponsiveFilemanager product, specifically versions up to 9.14.0.
How can an attacker exploit CVE-2026-18788?
A remote attacker can exploit the vulnerability in the `filemanager/dialog.php` file to bypass upload restrictions and upload arbitrary files to the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.