
WSSAT
WEB SERVICE SECURITY ASSESSMENT TOOL
api-security-testingdynamic-analysis-sandboxinginformation-gathering+3
390

WEB SERVICE SECURITY ASSESSMENT TOOL

This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP…

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

CVE CSRF DELETE ACCOUNT

CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)

CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.


CVE-2024–27630 Reference

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions