What is CVE-2026-18959?
A path traversal vulnerability has been identified in the `FileManagerController::destroyFiles` function in `panel-api.php` of yushine InnoShop up to version 0.8.2. This flaw allows remote attackers to manipulate file paths, potentially leading to unauthorized file access or deletion. Users should update InnoShop to the latest version and review file handling permissions immediately.
Azərbaycanca: yushine InnoShop-un 0.8.2 versiyasına qədər olan versiyalarında `panel-api.php` faylındakı `FileManagerController::destroyFiles` funksiyasında path traversal zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə fayl yollarını manipulyasiya etməyə imkan verir. InnoShop istifadəçiləri dərhal ən son versiyaya yeniləməli və fayl yükləmə məhdudiyyətlərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which file of InnoShop was the CVE-2026-18959 vulnerability found?
The vulnerability was found in the `FileManagerController::destroyFiles` function within the `panel-api.php` file.
What should users do to protect against the CVE-2026-18959 path traversal vulnerability?
Users should update InnoShop to the latest version immediately and review file handling permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.