Newly published CVEs detail severe application-layer vulnerabilities in three widely used web platforms. Shopizer 3.2.5 is affected by CVE-2026-36767, a critical path traversal flaw in the /content/images/add endpoint that lets an unauthenticated attacker send a crafted POST request and write arbitrary files to any writable path. JeeSite 5.15.1 is affected by CVE-2026-36760, where the fileMd5 parameter in /a/file/upload can be abused during chunked uploads to traverse directories and write arbitrary files with whitelisted suffixes to attacker-chosen filesystem locations; exploitation requires authenticated access with file upload permissions.
A separate high-severity issue, CVE-2026-36340, affects Krayin CRM 2.1.5 and allows remote code execution through the compose email function. The flaw was classified as CWE-94 and has been fixed in Krayin CRM 2.1.6. The Shopizer and JeeSite bugs were both classified as CWE-22 and carry high-impact CVSS ratings reflecting serious risk to confidentiality and integrity, with Shopizer also exposing availability. Public references for all three issues were added alongside their CVE records, including linked GitHub documentation and issue reports describing the vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A new CVE was published for Shopizer 3.2.5 covering a path traversal vulnerability in the /content/images/add endpoint. The flaw allows an unauthenticated attacker to send a crafted POST request and write arbitrary files to any writable path.
The CVE record for Krayin CRM's remote code execution issue was updated with its description, references, CWE-94 classification, and CVSS v3.1 scoring. The update documented that the vulnerability affected version 2.1.5 and had been fixed in version 2.1.6.
A new CVE was published for JeeSite v5.15.1 describing a path traversal flaw in the /a/file/upload endpoint. Authenticated attackers with file upload permissions could abuse the fileMd5 parameter during chunked uploads to write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.
Krayin CRM fixed a remote code execution vulnerability affecting version 2.1.5 in release 2.1.6. The flaw allowed remote attackers to execute arbitrary code through the compose email function.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.