CVE-2019-25579: Codnloc Phptransformer
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.
Affected products
- Codnloc Phptransformer: version 2016.9 only
Published 2026-03-21. Last modified 2026-06-17.