← back
CVE-2026-3695

SourceCodester Modern Image Gallery App delete.php path traversal

CVSS 6.9 MEDIUMEPSS 0.8%CWE-22
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →