August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-59384NVD

Vulnerability Summary

A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data.

We have already fixed the vulnerability in the following version:
Qfiling 3.13.1 and later
Severity Level
HIGH(8.1)
Published Date
Jan 2, 2026
Last Modified
Jan 22, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.
CVSS v4.0 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone