CVE-2026-93988
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
- Published Sep 19, 2026
- CVSS 7.1 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available