Critical Vulnerabilities Found in light0011 CMS and 92181 Markdown Parser

Critical Vulnerabilities Found in light0011 CMS and 92181 Markdown Parser

First seen 8 Sep 2026, 00:32 UTC Redpacketsecuritygithub.comvuldb.com 74.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been disclosed: CVE-2026-86305 in light0011 CMS and CVE-2026-86303 in 92181 Markdown parser. CVE-2026-86305 allows for unrestricted file uploads via a remote attack on the Upload::upload function, posing risks of malware delivery and data theft. CVE-2026-86303 involves an out-of-bounds read that can expose sensitive data or crash services. Both vulnerabilities were published on 2026-09-07 and affect systems using these products without available patches. The vulnerabilities are particularly dangerous for internet-facing installations and shared hosting environments. Immediate action is recommended, including disabling uploads and applying vendor fixes as they become available.

Key Points: • CVE-2026-86305 allows unrestricted file uploads in light0011 CMS. • CVE-2026-86303 poses an out-of-bounds read risk in 92181 Markdown parser. • Both vulnerabilities are actively exploitable and require urgent remediation.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-86305 published
A vulnerability in light0011 CMS allows remote unrestricted file uploads, risking malware and data theft.
Redpacketsecurity
2026-09-07
CVE-2026-86303 published
A vulnerability in 92181 Markdown parser can lead to out-of-bounds reads, exposing sensitive data.
Redpacketsecurity