Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments. Attackers can upload PHP payloads through the careers job application endpoint and execute system commands via POST requests to the uploaded file in the upload directory. | |
| Title | OpenCATS 0.9.4 Remote Code Execution via Resume Upload | |
| First Time appeared |
Opencats
Opencats opencats |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:opencats:opencats:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opencats
Opencats opencats |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T15:17:07.720Z
Reserved: 2026-02-01T11:24:18.717Z
Link: CVE-2021-47936
Updated: 2026-05-11T15:17:04.305Z
Status : Deferred
Published: 2026-05-10T13:16:29.830
Modified: 2026-05-12T14:24:15.210
Link: CVE-2021-47936
No data.
OpenCVE Enrichment
Updated: 2026-05-10T15:30:14Z