Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tarryhou

#35431of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2026-49149
7.5
2026-06-15
Unknown · Microweber · CVE-2026-12198
**Name of the Vulnerable Software and Affected Versions** Microweber versions prior to 2.0.21 **Description** A path traversal issue exists in the API Endpoint component. A remote attacker can manipulate the `cache path relative` argument within the `userfiles path()` function of the '/api nosession/thumbnail img' endpoint to access files and directories outside the intended folder. **Recommendations** Update to version 2.0.21 or later. As a temporary workaround, restrict access to the '/api nosession/thumbnail img' endpoint.