


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php…
Published:
4 augustus 2026 om 00:00:00
Alert date:
4 augustus 2026 om 21:04:59
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A security vulnerability (CVE-2026-18788) has been identified in Trippo ResponsiveFilemanager versions up to 9.14.0. The flaw exists in an unknown function within the filemanager/dialog.php file and allows unrestricted file upload. The vulnerability can be exploited remotely, and a public proof-of-concept exploit has already been released, increasing the risk of active exploitation. The vendor was notified but did not respond to the disclosure. The affected product is no longer maintained or supported by its developer, meaning no official patch or fix is expected. This end-of-life status combined with a public exploit makes this a significant risk for any installations still in use.
Technical details
Mitigation steps:
Affected products:
Trippo ResponsiveFilemanager 9.14.0 and below
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18788
https://github.com/fa1c4/security-advisories/tree/main/responsivefilemanager/PoC
https://github.com/sjmycz/cve/issues/8
https://vuldb.com/cve/CVE-2026-18788
https://vuldb.com/submit/857485
https://vuldb.com/submit/858233
https://vuldb.com/vuln/385789
https://vuldb.com/vuln/385789/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
