CVE-2019-25579: Codnloc Phptransformer

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

Affected products

  • Codnloc Phptransformer: version 2016.9 only

Published 2026-03-21. Last modified 2026-06-17.