CVE-2026-16219

Summary

A flaw has been found in Croogo CMS up to 4.0.7. This affects the function FileManager::isEditable of the file FileManager/src/Utility/FileManager.php of the component Admin File Manager. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
CroogoCMS4.0.0affected
CroogoCMS4.0.1affected
CroogoCMS4.0.2affected
CroogoCMS4.0.3affected
CroogoCMS4.0.4affected
CroogoCMS4.0.5affected
CroogoCMS4.0.6affected
CroogoCMS4.0.7affected

Weaknesses

  • CWE-22: Path Traversal

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References