CVE-2026-18959 PUBLISHED

yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal

Assigner: VulDB
Reserved: 05.08.2026 Published: 05.08.2026 Updated: 05.08.2026

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor yushine
Product InnoShop
Versions
  • Version 0.8.0 is affected
  • Version 0.8.1 is affected
  • Version 0.8.2 is affected

Credits

  • HackTen (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE