CVE-2024-44807: D-Zero Burgereditor

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.

Affected products

  • D-Zero Burgereditor: before 2.25.1 (fixed in 2.25.1)
  • D-Zero Burgereditor Limited Edition: before 2.25.1 (fixed in 2.25.1)

Published 2024-10-11. Last modified 2026-07-05.