CVE-2026-48866
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
01/06/2026
Last modified:
01/06/2026
Description
Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal.<br />
<br />
This issue affects Gravity Forms: from n/a through 2.10.0.1.
Impact
Base Score 3.x
9.60
Severity 3.x
CRITICAL



