CVE-2026-49849
xShop Unrestricted File Upload Leading to Remote Code Execution
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An unrestricted file upload vulnerability in xShop allows authenticated administrators to upload executable files. This could lead to remote code execution on the server, potentially resulting in a full system compromise. The issue is addressed in a later version.