VYPR

Committer

by Zentao

CVEs (1)

  • CVE-2026-2552MedFeb 16, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of the argument filePath leads to path traversal. Upgrading to version 21.7.9 can resolve this issue.…