7.2
CVSSv3

CVE-2025-26356

CVSSv4: NA | CVSSv3: 7.2 | CVSSv2: NA | VMScore: 820 | EPSS: 0.00573 | KEV: Not Included
Published: 12/02/2025 Updated: 12/02/2025

Vulnerability Summary

Path Traversal in Q-Free MaxTime <= 2.11.0 Enables Sensitive File Overwrite

A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote malicious user to overwrite sensitive files via crafted HTTP requests.

Vulnerable Product Search on Vulmon Subscribe to Product

q-free maxtime