CVE-2026-28507: Withknown Known

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4.

Affected products

  • Withknown Known: before 1.6.4 (fixed in 1.6.4)

Published 2026-03-06. Last modified 2026-06-17.