No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar Upload. The manipulation of the argument Username leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal | |
| First Time appeared |
Weiqingwen
Weiqingwen spring-boot-forum |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:weiqingwen:spring-boot-forum:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Weiqingwen
Weiqingwen spring-boot-forum |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-23T22:45:09.921Z
Reserved: 2026-09-23T15:28:20.252Z
Link: CVE-2026-96678
No data.
Status : Received
Published: 2026-09-23T23:18:49.923
Modified: 2026-09-23T23:18:49.923
Link: CVE-2026-96678
No data.
OpenCVE Enrichment
Updated: 2026-09-24T00:30:07Z