CVE-2026-81275
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-22
- Published
- 2026-09-10
- Last modified
- 2026-09-10
Affected products
- Youzify Youzify
Weakness type
Related vulnerabilities
- CVE-2026-76652 — Authenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600
- CVE-2026-88046 — rclone: source object names can escape the configured root on upload
- CVE-2026-88014 — rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
- CVE-2026-88940 — knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
- CVE-2026-88938 — knowns through 0.33.0 Path Traversal via code.find MCP tool
- CVE-2026-88937 — knowns through 0.33.0 Path Traversal via Template Engine
- CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability
- CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal