Search CVE reports


Toggle filters

1 result


CVE-2026-60102

Medium priority
Needs evaluation

Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing...

1 affected package

php-horde-vfs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-horde-vfs Not in release Not in release Not in release Needs evaluation
Show less packages