CVE-2026-93988

CVE-2026-93988 published: QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass dir...

View full NVD advisory → ← Back to CVE watch