CVE-2026-28674 | danvei233 xiaoheiFS up to 0.3.x AdminPaymentPluginUpload plugins/payment/ unrestricted upload (GHSA-hcj4-gfvq-qv4p / EUVD-2026-12702)
A vulnerability was found in danvei233 xiaoheiFS up to 0.3.x. It has been classified as critical. Affected is an unknown function of the file plugins/payment/ of the component AdminPaymentPluginUpload. Performing a manipulation results in unrestricted upload.
This vulnerability is known as CVE-2026-28674. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.