CVE-2026-18645 | danpros HTMLy up to 3.1.1 Admin Content Endpoint /system/admin/admin.php add_content oldfile path traversal
A vulnerability has been found in danpros HTMLy up to 3.1.1 and classified as critical. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal.
This vulnerability was named CVE-2026-18645. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More