VYPR

hubzero-cms

by Hubzero

CVEs (1)

  • CVE-2026-92970HigSep 17, 2026
    risk 0.57cvss 8.8epss

    HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the project repository. Attackers can supply traversal sequences in upload parameters to write files to…