CYBERHAWK / CVE / CVE-2026-41463

CVE-2026-41463

ProjeQtor

HIGH CVSS 8.8 vibe

The flaw

ZipSlip path traversal in plugin upload allows authenticated attackers to write webshells.

What to do

Update to version 12.4.4 or later

▸ Scan my repo for CVE-2026-41463

References

First seen 2026-05-01 · Tracked by PickBits CyberHawk · Weekly CVE digest