CVE-2026-36767Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-04-30: 2Mentions · 2026-05-12: 4Technical Details · 2026-04-30: 2Technical Details · 2026-05-12: 304-3005-12
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure2
2026-05-124
Disclosure2General2
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-36767 A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST … https://www.cve.org/CVERecord?id=CVE-2026-36767

    Post summary

    The text discloses a path traversal flaw in shopizer v3.2.5 that permits arbitrary file writes via crafted POST requests, but it provides no PoC, exploit code, or patch information.

    00020149
    57.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-36767 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This brief advisory announces CVE-2026-36767 with a critical severity and provides its CVSS vector, but offers no PoC, exploit, or mitigation details.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-36767 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable…

    Post summary

    The post publishes details of a critical path traversal vulnerability in shopizer v3.2.5, including CVSS metrics and a vulnerability description, but offers no PoC, exploit code, or patch information.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-36767 (CVSS 10) — multiple products. CVE: CVE-2026-36767 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces a critical CVE with CVSS 10 and describes its severity, but it does not provide any PoC, exploit, patch, or evidence of exploitation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-36767-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet merely links to an advisory for CVE‑2026‑36767 without providing any additional details on exploitation, patches, or technical specifics.

    0000024
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-36767 A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST … https://www.cve.org/CVERecord?id=CVE-2026-36767 ----- Traducción: CVE-2026-36767 Una… http://infoflow.cloud`

    Post summary

    CVE‑2026‑36767 is a path traversal flaw in shopizer v3.2.5 that permits attackers to write arbitrary files via crafted POST requests, yet no PoC, exploit tool, active exploitation, or patch is mentioned.

    0000014
    74 followersView on X

Explore more