8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.
AI Analysis
Path Traversal vulnerability in VikBooking Hotel Booking Engine & PMS plugin, allowing arbitrary file deletion
Basic Information
ID
CVE-2026-42737
Source
Patchstack
Published
May 27, 2026 at 09:49
Affected Product
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Affected Versions
e4jvikwp VikBooking Hotel Booking Engine & PMS 0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Version
<= 1.8.9