CVE-2026-3795 identifies a critical path traversal vulnerability (CWE-22) in doramart DoraCMS 3.0.x, specifically within the `createFileBypath` function. This flaw carries a CVSS score of 9.8 CRITICAL, enabling an unauthenticated, remote attacker to achieve high impact on confidentiality, integrity, and availability without requiring user interaction. Although exploit code has been publicly released, there is currently no evidence of active exploitation, KEV listing, or significant community discussion, and its EPSS score remains very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:html-js:doracms:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.