CVE-2026-37068EPSS p42.6%
CVE-2026-37068CVE-2026-37068
Description
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 0.53% probability of exploitation · percentile 42.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-02 |