Brandfolder Vulnerabilities and Affected Products
Vulnerabilities associated with Brandfolder.
Products
Clear product- Brandfolder1 vulnerability
- Brandfolder – Digital Asset Management Simplified.1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2016-20080MEDIUM | WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.phpWordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code. CWE-98Jun 15, 2026 | CVSS6.9v4.0 | EPSS0.39% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |