CVE-2026-45233General

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers can pass unsanitized traversal sequences directly to file_exists() and rename() functions in admin.php without canonicalization or directory boundary enforcement to cause unintended relocation of any file writable by the web server process to an attacker-specified draft location.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-25: 106-25
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Midhun Mohanan 🇮🇳@mrgr4yhat
    General

    Another one added to the bucket ! CVE-2026-45233 https://www.vulncheck.com/advisories/htmly-cms-path-traversal-via-oldfile-parameter-in-autosave #CVE #SecurityResearch #AppSec #CyberSecurity #InfoSec

    Post summary

    The tweet cites CVE-2026-45233 and links to an advisory but offers no further details, PoC, exploit, patch, or technical information.

    0000058
    91 followersView on X

Explore more