CVE-2026-7107Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-27: 2Technical Details · 2026-04-27: 104-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-7107 A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of th… https://www.cve.org/CVERecord?id=CVE-2026-7107

    Post summary

    CVE-2026-7107 is announced as a weakness in code-projects' Invoice System (Laravel 1.0) affecting an unknown function in /company, with limited technical detail and no evidence of exploitation, patch, or PoC.

    00000102
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7107 Unrestricted File Upload Vulnerability in Code-Projects In... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7107 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A brief tweet references CVE‑2026‑7107 and provides a link to a vulnerability detail page, with no additional technical or exploit information.

    0000048
    4.0K followersView on X

Explore more