CVE-2026-36767

shopizer 3.2.5 - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

Scores

EPSS 0.0006
EPSS Percentile 19.5%

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

Status published
Published Apr 30, 2026
Tracked Since Apr 30, 2026