CVE-2024-11838: Plextrac
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocumented API endpoint.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
Affected products
- Plextrac Plextrac: from 1.61.3, before 2.8.1 (fixed in 2.8.1)
Published 2024-12-13. Last modified 2026-06-17.