Unknown · Croogo Cms · CVE-2026-16219
**Name of the Vulnerable Software and Affected Versions**
Croogo CMS versions prior to 4.0.8
**Description**
A path traversal flaw exists in the Admin File Manager component. The issue resides in the `isEditable()` function within the `FileManager/src/Utility/FileManager.php` file. This flaw allows a remote attacker to manipulate file paths to access unauthorized directories.
**Recommendations**
Update Croogo CMS to version 4.0.8 or later.
As a temporary mitigation, restrict access to the Admin File Manager component.