CVE-2026-40185 - Missing Authorization on Immich Trip Photo Routes in TREK
CVE ID :CVE-2026-40185
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization che...
Related Vulnerabilities
- CVE-2026-1924: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers MEDIUM
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-3358: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthori MEDIUM
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
Related Coverage
Threat Actors