CVE-2026-40184 - Unauthenticated Access to Uploaded Files in TREK
CVE ID :CVE-2026-40184
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos withou...
Related Vulnerabilities
- CVE-2026-4162: The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and HIGH
- CVE-2026-33698: Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise N/A
- CVE-2026-40191: ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. N/A
- CVE-2026-35668: OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa HIGH
- CVE-2026-35649: OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to MEDIUM
Related Coverage
Threat Actors