
CVE-2026-66493
The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions
data-exfiltrationexploitationpenetration-testing+3

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP…

CVE CSRF DELETE ACCOUNT

CVE-2024-46627 - Incorrect access control in BECN DATAGERRY v2.2 allows attackers to > execute arbitrary commands via crafted web requests.

CVE-2024–27630 Reference


CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)

WEB SERVICE SECURITY ASSESSMENT TOOL