CVE-2026-95264: Path Traversal
Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to unlink() without path traversal or directory validation.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated Feehi CMS backend user must have permission to edit articles. The issue is limited to files that are writable by the PHP process.
What access does an attacker need to delete a file?
The attacker needs backend authentication and article edit permission, then can manipulate article image metadata used to build the path passed to unlink().
How can I determine whether my deployment is affected?
Feehi CMS version 2.1.1 is identified as affected. Exposure depends on whether backend users have article edit permission and on which filesystem locations are writable by the PHP process.