CVE intelligence

CVE-2026-86100

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature.

Published 2026-09-05 · CVSS

medium

NIST record