MEDIUM
Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal
Published Feb 22, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.99%
Description
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 101.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7683 Advisory
- https://vuldb.com/?ctiid.347319 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.347319 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.755215 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.yuque.com/la12138/pa2fpb/lxngf3d07uyd0nwp?singleDoc exploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-7683 | Advisory | |
| https://vuldb.com/?ctiid.347319 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.347319 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.755215 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.yuque.com/la12138/pa2fpb/lxngf3d07uyd0nwp?singleDoc | exploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 22, 2026
Updated Feb 25, 2026
Reserved Feb 21, 2026
Link CVE-2026-2953
CISA Vulnrichment
Updated Feb 25, 2026
Red Hat
No data
GitHub
No data