CVE-2026-28674 is a high-severity Remote Code Execution (RCE) vulnerability impacting danvei233 xiaoheifs versions up to 0.3.15. This flaw allows an authenticated administrator to upload arbitrary executable files through the `AdminPaymentPluginUpload` endpoint, which are then automatically executed by a background service. With a CVSS score of 7.2 (High), this network-based vulnerability enables full compromise of confidentiality, integrity, and availability. Despite its critical impact, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.0CPE matchmatch criteria | cpe:2.3:a:danvei233:xiaoheifs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.