PT-2026-63611 · Unknown · Rereplacer Pro

CVE-2026-65754

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ReReplacer Pro extension (affected versions not specified)
Description Insecure path handling in the ReReplacer Pro extension allows XML include paths to read files located outside the site directory. This is a directory traversal issue where the application does not properly validate the file paths provided in XML includes, potentially allowing unauthorized access to sensitive files on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65754

Affected Products

Rereplacer Pro