Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 22 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mothra Default Path Upload Exploit |
Fri, 22 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mothra Default File Path Bypass in HTML Upload Forms | |
| Weaknesses | CWE-22 |
Fri, 22 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
ssvc
|
Fri, 22 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Mothra Default File Path Bypass in HTML Upload Forms | |
| First Time appeared |
9front
9front 9front |
|
| Weaknesses | CWE-22 | |
| Vendors & Products |
9front
9front 9front |
Fri, 22 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website with a malicious default file path, and then conceal this form element. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: 9front
Published:
Updated: 2026-05-22T12:36:11.446Z
Reserved: 2026-05-19T21:39:13.119Z
Link: CVE-2026-9053
Updated: 2026-05-22T12:25:29.106Z
Status : Deferred
Published: 2026-05-22T04:16:28.430
Modified: 2026-06-17T11:04:46.603
Link: CVE-2026-9053
No data.
OpenCVE Enrichment
Updated: 2026-05-22T17:30:06Z