Product
HortusFox versions prior to 6.2 are vulnerable to remote code execution via an insufficient validation flaw in the theme import process allowing arbitrary file uploads to the web root.