CVE-2016-10759: Precurio

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.

Affected products

Published 2019-05-24. Last modified 2026-06-17.