CVE-2026-108101: HortusFox through 6.3 Unrestricted File Upload via Plant Attachments

Published Oct 9, 2026
·
Updated

HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.

Affected Software

1 affected component
HortusFox HortusFox<=6.3

Event History

Oct 9, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an authenticated HortusFox account with access to upload plant attachments through /plants/attachments/add. The available data does not identify any further role restriction.

2

When does an uploaded PHP file lead to server-side code execution?

PHP upload becomes code execution where the server does not enforce the .htaccess protection for the public/attachments/ directory. In that configuration, a PHP file stored in the attachment directory may be executed by the web server.

3

Are all deployments exposed to the same impact?

No. HTML or SVG uploads can be used for stored cross-site scripting, while PHP uploads require an environment in which .htaccess is unenforced to execute code. The vulnerability affects HortusFox through version 6.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203