Skip to content

Known CVE

Pheditor 2.0.1-2.0.3 - OS Command Injection

Pheditor 2.0.1 to - 2.0.4 contains an OS command injection caused by improper sanitization of the 'dir' POST parameter in the terminal action handler, letting authenticated users execute arbitrary OS commands with web server privileges.

CVE-2026-48030

Critical2026CVSS 9.9CWE-78

cve2026 · rce · pheditor · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website