CVE-2026-40184 - Unauthenticated Access to Uploaded Files in TREK
CVE ID :CVE-2026-40184
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos withou...
Related Vulnerabilities
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-40242: Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint HIGH
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-5226: The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors