A zip slip vulnerability in the /DesignTools/SkinList...
Critical severity
Unreviewed
Published
Feb 13, 2026
to the GitHub Advisory Database
•
Updated Feb 13, 2026
Description
Published by the National Vulnerability Database
Feb 13, 2026
Published to the GitHub Advisory Database
Feb 13, 2026
Last updated
Feb 13, 2026
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
References