← Back to the live CVE advisory feed

CVE-2026-100715: Product identification pending

Severity
8.5 (HIGH)
Vendor
FROXLOR THROUGH
Affected versions
Through 2.3.10
Patch status
Unknown
Published
2026-09-26T14:16:57.427
Modified
2026-09-26T14:16:57.537

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences a symlink used either as an intermediate path component or as the final component. An authenticated customer who can write to the FTP home directory can plant a symlink between task insertion and cron execution, causing the root cron job to recursively delete arbitrary directory trees, resulting in cross-tenant data destruction and host denial of service. This issue is fixed in Froxlor 2.3.12.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 27, 2026 12:00 AM UTC
248 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-97163
UP plugin for Joomla
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-18143
Request a Quote for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85984
miniOrange OTP Login, Verification and SMS Notifications
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-82901
Ultra Addons for Contact Form 7
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94132
AcyMailing Enterprise extension for Joomla
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-100706
kyverno PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100714
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100716
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-97160
UP plugin for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-100720
froxlor PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-94130
YouTube Gallery extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-100606
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100607
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100684
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-97161
UP plugin for Joomla
Reporter: SECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-100551
OpenClaw PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-100567
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-100683
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-100597
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-96524
MCP Server for WordPress PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-100676
stoatchat PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-77203
Groups – Memberships and Access Control
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-100520
Laranode PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100544
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100552
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100557
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100558
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100568
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100575
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100580
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100586
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100587
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100588
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100589
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100596
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100599
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100603
clawhub PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100608
Flowise
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100614
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100615
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100617
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100618
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100619
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100622
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100623
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100625
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100628
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100631
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100644
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100656
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100657
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100660
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100661
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100662
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100663
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100664
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100665
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100669
grav PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100670
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100672
grav PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100682
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100689
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100690
hugo PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100692
hugo PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100700
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100711
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100559
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100561
OpenClaw PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100585
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100612
capgo.app
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100639
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100640
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100641
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100645
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100646
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100671
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100680
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100686
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100693
hugo PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100530
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100570
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100633
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100643
siyuan PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100715
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100717
froxlor PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-100673
grav PATCH
Reporter: DISCLOSURE
8.4
HIGH
VIEW RECORD
CVE-2026-100636
siyuan PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100637
siyuan PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100638
siyuan PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100653
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100678
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100685
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100703
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100704
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100705
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-100707
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-94131
AcyMailing extension for Joomla
Reporter: SECURITY
8.3
HIGH
VIEW RECORD
CVE-2026-97162
UP plugin for Joomla
Reporter: SECURITY
8.3
HIGH
VIEW RECORD
CVE-2026-100574
Product identification pending PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-100635
siyuan PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.