NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-36762
Summary

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

Publication Date May 1, 2026, 3:16 a.m.
Registration Date May 1, 2026, 4:07 a.m.
Last Update May 1, 2026, 3:16 a.m.
Related information, measures and tools
Common Vulnerabilities List