๐Ÿ” CVE Alert

CVE-2026-93988

MEDIUM 6.5

QloApps through 1.7.0 Arbitrary File Read via getEmailHTML

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.

CWE CWE-22
Vendor webkul
Product qloapps
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for webkul qloapps

Be the first to know when new medium vulnerabilities affecting webkul qloapps are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

webkul / qloapps
0 โ‰ค 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Qloapps/QloApps/pull/1719 github.com: https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715 github.com: https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051 hackmd.io: https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal github.com: https://github.com/Qloapps/QloApps vulncheck.com: https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml

Credits

๐Ÿ” leediay153