CVE-2026-40184 - Unauthenticated Access to Uploaded Files in TREK
CVE ID :CVE-2026-40184
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos withou...
Related Vulnerabilities
- CVE-2026-1263: The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, MEDIUM
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
- CVE-2026-33736: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including MEDIUM
- CVE-2026-5217: The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin f HIGH
- CVE-2026-35647: OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass MEDIUM
Related Coverage
Threat Actors