CVE-2026-75327
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
- Published Aug 26, 2026
- CVSS 9.8 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)