CVE-2026-18644: danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal
A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component Delete Username Endpoint. Such manipulation of the argument File leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18644?
CVE-2026-18644 has a medium severity rating of 5.4.
How do I fix CVE-2026-18644?
To fix CVE-2026-18644, update danpros HTMLy to version 3.1.2 or higher.
What type of vulnerability is CVE-2026-18644?
CVE-2026-18644 is classified as a path traversal vulnerability.
Can CVE-2026-18644 be exploited remotely?
Yes, CVE-2026-18644 can be exploited remotely through manipulation of the delete username endpoint.
What components are affected by CVE-2026-18644?
The affected component is the Delete Username Endpoint located in /system/htmly.php of danpros HTMLy.