MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 15 h ago, last 15 h ago, peak #12

HortusFox vulnerability allows authenticated file upload attacks

Original: 🚨 EUVD-2026-95792 πŸ“Š Score: 7.7/10 (CVSS v3.1) πŸ“¦ Product: hortusfox-web 🏒 Vendor: danielbrendel πŸ“… Updated: 2026-10-09 πŸ“ H

A medium-to-high severity vulnerability, tracked as EUVD-2026-95792 with a CVSS score of 7.7, has been disclosed in HortusFox (hortusfox-web), a self-hosted plant management application by developer danielbrendel. Versions through 6.3 contain an unrestricted file upload flaw in the PlantAttachmentModel, letting authenticated users store arbitrary files on the server. Admins running the app are advised to check for updates and restrict uploads.

Why now: Security feeds are circulating the new advisory so self-hosters can patch before exploitation.

HortusFoxdanielbrendelEUVD-2026-95792

Open on mastodon β†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1627863