Known CVE
Pheditor 2.0.1-2.0.3 - OS Command Injection
Pheditor 2.0.1 to - 2.0.4 contains an OS command injection caused by improper sanitization of the 'dir' POST parameter in the terminal action handler, letting authenticated users execute arbitrary OS commands with web server privileges.
CVE-2026-48030
Critical2026CVSS 9.9CWE-78
cve2026 · rce · pheditor · authenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website