CRITICAL 9.1 CVE-2026-49849 Published 21 Aug 2026

Laravel-based xShop RCE via File Upload

Worried this affects one of your servers?

xShop, an open-source e-commerce platform built on Laravel, is affected.

An authenticated administrator can exploit an Unrestricted File Upload vulnerability in version 3.0.3 to upload executable files like .php.

Uploading a specially crafted PHP file allows an attacker to achieve Remote Code Execution (RCE), potentially leading to a full system compromise.

Version 3.0.4 addresses this issue.

Reference: CVE-2026-49849 on NVD

← Back to Security News