Launch Week Day 1: Announcing Security Design Review
CRITICAL 10.0 Maven

Shopizer has a path traversal issue

GHSA-f5w4-7ccj-5m75 · CVE-2026-36767

Published · Modified

Description

A path traversal vulnerability in the /content/images/add endpoint of shopizer through version 3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

Ready to move

Start Securing

Free, no credit card | First findings in minutes