CVE-2026-40184 - Unauthenticated Access to Uploaded Files in TREK
CVE ID :CVE-2026-40184
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos withou...
Related Vulnerabilities
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
- CVE-2026-34971: Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift CRITICAL
- CVE-2021-47960: A files or directories accessible to external parties vulnerability in Synology SSL VPN Client befor MEDIUM
- CVE-2026-5207: The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all v MEDIUM
- CVE-2026-33618: Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController HIGH
Related Coverage
Threat Actors