CRITICAL
9.1 CVE-2026-49849 Published 21 Aug 2026
Laravel-based xShop RCE via File Upload
Worried this affects one of your servers?
xShop, an open-source e-commerce platform built on Laravel, is affected.
An authenticated administrator can exploit an Unrestricted File Upload vulnerability in version 3.0.3 to upload executable files like .php.
Uploading a specially crafted PHP file allows an attacker to achieve Remote Code Execution (RCE), potentially leading to a full system compromise.
Version 3.0.4 addresses this issue.
Reference: CVE-2026-49849 on NVD
← Back to Security News