CVE-2026-41463Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with upload permissions to write files outside the intended extraction directory by crafting ZIP archives with directory traversal sequences. Attackers can exploit unvalidated archive extraction to write a PHP webshell to a web-accessible directory and achieve remote code execution with the privileges of the web server process.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Technical Details · 2026-04-27: 204-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-41463 ProjeQtor versions 7.0 through 12.4.3 contain a ZipSlip path traversal vulnerability in the plugin upload functionality that allows authenticated attackers with uploa… https://www.cve.org/CVERecord?id=CVE-2026-41463

    Post summary

    The snippet announces that CVE‑2026‑41463 is a ZipSlip path traversal flaw in ProjeQtor plugin uploads, but provides no PoC, exploit, patch, or active exploitation information.

    0000078
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41463 Path Traversal Vulnerability in ProjeQtor 7.0-12.4.3 Plugin Upload Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41463

    Post summary

    The text lists CVE-2026-41463 as a path traversal flaw in ProjeQtor’s plugin upload function, provides a link to more details, but offers no PoC, exploit, or patch information.

    0000039
    4.0K followersView on X

Explore more