CVE-2016-20052Disclosure(snewscms / snews)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for snewscms snews systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snews

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
snews

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-04: 3Mentions · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-04: 1Exploit Tool / Code · 2026-04-04: 1Technical Details · 2026-04-04: 3Technical Details · 2026-04-05: 104-0404-05
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-043
Disclosure2PoC1
2026-04-051
General1
Full discourse4 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2016-20052 | CVSS 9.8 🔴 CVE-2018-25254 | CVSS 9.8 🟠 CVE-2026-3666 | CVSS 8.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑CVSS CVEs with no additional detail on exploitation, PoC, or patching, presenting a brief vulnerability overview.

    0000036
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2016-20052 Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snew… https://www.cve.org/CVERecord?id=CVE-2016-20052

    Post summary

    The post announces CVE-2016-20052 in Snews CMS 1.7, describing an unrestricted file‑upload flaw that lets unauthenticated attackers upload PHP executables.

    00000152
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2016-20052: CRITICAL] Snews CMS 1.7 has a critical unrestricted file upload vulnerability allowing attackers to upload malicious PHP files for remote code execution in the snews_files directory.#cve,CVE-2016-20052,#cybersecurity https://cvefind.com/CVE-2016-20052

    Post summary

    The post discloses a critical unrestricted file‑upload vulnerability in Snews CMS 1.7, enabling remote code execution via malicious PHP files, but provides no exploit code, patch, or evidence of active exploitation.

    0000054
    619 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2016-20052: Snews CMS 1.7 Unrestricted File ... Unauthenticated RCE via direct PHP upload to snews_files - zero friction exploitation with public PoC makes this a driv... https://zerodaysignal.com/vulnerability/CVE-2016-20052 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet highlights CVE‑2016‑20052, an unauthenticated RCE in Snews CMS via PHP file upload, and notes a public proof‑of‑concept is available, but it does not mention active exploitation, a patch, or any debunking.

    0000096
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnewscmssnews---

Explore more