CVE-2025-50971: Abantecart

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensitive system files via the template parameter to index.php.

Affected products

Published 2025-08-26. Last modified 2026-06-17.