CVE-2019-17199: Webpagetest

High severity, CVSS 7.5. EPSS: 10% chance of exploitation in the next 30 days.

www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.

Affected products

Published 2019-10-05. Last modified 2026-06-17.