CVE-2026-8133Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of the component Shares Filelist API. Such manipulation of the argument order leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is e20ec58414103f781858f2951d178e19b1736664. A patch should be applied to remediate this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-09)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Technical Details · 2026-05-08: 105-0805-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-092
Disclosure1General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-8133 A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php… https://www.cve.org/CVERecord?id=CVE-2026-8133

    Post summary

    A CVE-2026-8133 vulnerability for zyx0814 FilePress up to 2.2.0 is reported, referencing an unknown issue in dzz/shares/admin.php, but the description lacks technical details, patches, or exploitation information.

    00010243
    57.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8133 A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php… https://www.cve.org/CVERecord?id=CVE-2026-8133 ----- Traducción: CVE-2026-8133 Se … http://infoflow.cloud`

    Post summary

    The post briefly announces CVE-2026-8133 affecting zyx0814 FilePress up to version 2.2.0, linking to the CVE record but providing minimal technical detail or actionable information.

    0000030
    76 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8133 SQL Injection in zyx0814 FilePress Up to 2.2.0 Shares Filelist API https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8133

    Post summary

    This brief notice announces a SQL injection vulnerability in FilePress version 2.2.0’s Filelist API, providing minimal technical details and a link to additional information.

    0000055
    4.0K followersView on X

Explore more