CVE-2026-66914

Summary

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.

Affected Software

VendorProductVersion RangeStatus
seblod.comSEBLOD extension for Joomla1.0.0-3.29.0affected
seblod.comSEBLOD extension for Joomla4.0.0-4.6.0affected
seblod.comSEBLOD extension for Joomla5.0.0-6.0.0affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References