CVE-2026-40184 - Unauthenticated Access to Uploaded Files in TREK
CVE ID :CVE-2026-40184
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos withou...
Related Vulnerabilities
- CVE-2026-1263: The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, MEDIUM
- CVE-2026-34424: Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access to CRITICAL
- CVE-2026-33736: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including MEDIUM
- CVE-2026-35596: Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug MEDIUM
- CVE-2026-6057: FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload A CRITICAL
Related Coverage
Threat Actors