CVE-2026-84063 PUBLISHED

Assigner: jpcert
Reserved: 01.09.2026 Published: 10.09.2026 Updated: 10.09.2026

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor D-ZERO CO.,LTD.
Product BurgerEditor
Versions
  • Version 3.2.0 through 3.4.0 is affected
Vendor D-ZERO CO.,LTD.
Product BurgerEditor
Versions
  • Version 2.28.0 through 2.30.0 is affected

References

Problem Types