CVE-2026-93506: SveltyCMS File Upload Endpoint upload-media server-side request forgery
A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. This patch is called 05b4f9efeb79e9d72a693232334d7529687f896f. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SveltyCMS File Upload Endpoint (/mediagallery/upload-media)to a version that resolves this vulnerability.Patch 05b4f9efeb79e9d72a693232334d7529687f896f
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which component should be prioritized for remediation?
Prioritize the File Upload Endpoint at /mediagallery/upload-media. The vulnerable processing is described as affecting SveltyCMS version 0.0.6.
Is a fix available?
Yes. The available patch is identified as commit 05b4f9efeb79e9d72a693232334d7529687f896f, and applying it is recommended.