CVE-2026-63303: A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolvi
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read contents of files located in the sibling directory of the webroot via a crafted HTTP request containing ../ sequences in the URI.
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-63303
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-633030.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63303 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for A Path Traversal
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-67309: Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kuberne…nvd · 2026-08-01
- mediumCVE-2026-15601: The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulner…nvd · 2026-08-01
- highCVE-2026-15450: The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary f…nvd · 2026-08-01
- unknownCVE-2026-15244: The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against direc…nvd · 2026-08-01
- highGHSA-6hm5-jgcp-p838: Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary Fi…ghsa · 2026-07-31
- highGHSA-xh95-f55m-82fw: Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that a…ghsa · 2026-07-31
More from NVD Recent CVEs
- unknownCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…2026-08-01
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01