CVE-2026-96824
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
CVSS
6.8
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-22
Not enough EPSS history yet.
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972426.8 MED—
———Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.3hCVE-2026-941237.5 HIG—
———Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.3hCVE-2026-750987.5 HIG—
———The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The endpoint's only authentication gate relies on a nonce and token that are both publicly emitted as JavaScript globals on any page rendering the [pdapp-studio-page] shortcode, making them freely obtainable by anonymous visitors.3hCVE-2026-1024576.5 MED—
———EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.8hCVE-2026-1028434.7 MED—
———A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.3hCVE-2026-86136——
——0A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.17h