CVE-2026-95265

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, allowing an attacker to make the server probe internal HTTP services through response differences.

https://github.com/liufee/cms
https://github.com/tao0845/CVE-Request/blob/main/CVE-2026-95265.md