


Perceptive Security
SOC/SIEM Consultancy

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted…
Published:
29 April 2026 at 22:00:00
Alert date:
30 April 2026 at 19:02:01
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A path traversal vulnerability has been identified in shopizer v3.2.5, specifically in the /content/images/add endpoint. This security flaw allows attackers to write arbitrary files to any writable path on the system through crafted POST requests. The vulnerability enables unauthorized file upload and potential system compromise by bypassing normal file path restrictions. Attackers can exploit this weakness to upload malicious files to sensitive directories, potentially leading to remote code execution or data manipulation. The issue affects the popular open-source e-commerce platform shopizer and has been documented in the project's GitHub repository.
Technical details
Mitigation steps:
Affected products:
shopizer
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-36767
https://github.com/shopizer-ecommerce/shopizer
https://github.com/shopizer-ecommerce/shopizer/issues/1091
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
