CVE-2026-84063
nicheUnrestricted File Upload in BurgerEditor 3.2.0–3.4.0 Enables PHP Code Execution
BurgerEditor versions 3.2.0 through 3.4.0 are affected by an unrestricted file upload flaw (CWE-434) that allows files with dangerous types, such as PHP scripts, to be uploaded without restriction. The flaw is triggered when an attacker who is able to log in to the product abuses the upload functionality to place an arbitrary file on the server. By uploading a malicious PHP file, the attacker can potentially achieve arbitrary PHP code execution on the host, effectively gaining remote code execution under the web server's privileges. Any deployment running BurgerEditor 3.2.0 through 3.4.0 is affected, and the CVSS 4.0 score of 8.5 (high) reflects that exploitation requires an authenticated attacker with elevated privileges. There is currently no public proof of concept, the flaw is not listed in CISA's KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Upgrade BurgerEditor to a fixed release outside the affected 3.2.0–3.4.0 range as specified in the vendor/JPCERT advisory. Until patched, restrict upload-capable accounts, enforce strict allowlists on uploaded file types, and block PHP execution in upload directories. Audit upload directories for unexpected or recently added .php files that could indicate prior exploitation.
| BurgerEditor project BurgerEditor | 3.2.0 through 3.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused.
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.