Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the intended web root.
History

Wed, 13 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the intended web root.
Title Joomla com_fabrik 3.9.11 Directory Traversal via image.php
First Time appeared Fabrikar
Fabrikar fabrik
Weaknesses CWE-22
CPEs cpe:2.3:a:fabrikar:fabrik:3.9.11:*:*:*:*:*:*:*
Vendors & Products Fabrikar
Fabrikar fabrik
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-13T14:22:31.533Z

Updated: 2026-05-13T14:22:31.533Z

Reserved: 2026-05-13T13:47:51.522Z

Link: CVE-2020-37219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-13T16:16:33.290

Modified: 2026-05-13T17:07:21.030

Link: CVE-2020-37219

cve-icon Redhat

No data.