CVE-2026-14635 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b Vendor Multi-Image Endpoint AddProduct.php folder path traversal (GHSA-6whv-r5hm-vcjr)
A vulnerability marked as critical has been reported in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the argument folder results in path traversal.
This vulnerability is cataloged as CVE-2026-14635. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More