Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Traveler — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Traveler, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security advisories for the Traveler product, focusing on specific weakness types and associated tags. It collects reported vulnerabilities and their corresponding remediation data within the defined coverage period. Readers can track vendor advisories, analyze weakness patterns, and review the product's historical security posture. The content serves as a consolidated reference for security teams assessing risk exposure and compliance requirements. By centralizing this information, the page supports efficient triage and prioritization of security issues. It highlights recurring vulnerability classes and their frequency, enabling proactive defense strategies. The data is presented objectively, without promotional language, to facilitate clear decision-making. Users can filter entries by severity, publication date, or impact scope to tailor their review. This aggregation aids in identifying systemic issues that may require broader architectural changes. It also helps in benchmarking against industry standards for similar products. The focus remains strictly on factual reporting of known flaws and their resolutions. No individual CVE identifiers are listed in this introductory overview, but each entry links to detailed technical reports. The time range reflects all publicly disclosed incidents since the product's initial release. This ensures comprehensive historical context for long-term security planning. The page updates periodically to include newly published advisories. It supports both automated integration via API and manual analysis. Security researchers and compliance officers benefit from the structured format. The lack of marketing tone ensures professional reliability. All information is sourced from verified public disclosures. This approach maintains trust and transparency. The aggregation reduces the need to cross-reference multiple databases. It streamlines the process of understanding cumulative risk. The product-specific focus allows for targeted mitigation efforts. Overall, this page provides essential context for evaluating the security landscape of Traveler.

Vendor: shinetheme

CVE ID Title CVSS Severity Published
CVE-2026-93947 WordPress Traveler theme <= 3.2.9 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-10-09
CVE-2026-56547 An input reflection vulnerability affects HCL Traveler CWE-20 3.5 Low 2026-08-26
CVE-2026-21790 HCL Traveler is susceptible to a weak default HTTP header validation vulnerability CWE-346 6.3 Medium 2026-03-24
CVE-2026-21783 HCL Traveler is affected by sensitive information disclosure CWE-209 4.3 Medium 2026-03-24
CVE-2026-25449 WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2026-03-18
CVE-2026-24367 WordPress Traveler theme < 3.2.8 - SQL Injection vulnerability CWE-89 8.5 High 2026-01-22
CVE-2025-67917 WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-01-08
CVE-2025-64372 WordPress Traveler theme < 3.2.6 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-12-18
CVE-2025-64371 WordPress Traveler theme < 3.2.6 - SQL Injection vulnerability CWE-89 8.5 High 2025-12-18
CVE-2025-64373 WordPress Traveler theme < 3.2.6 - Local File Inclusion vulnerability CWE-98 8.1 High 2025-12-18
CVE-2025-63028 WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-12-09
CVE-2025-59012 WordPress Traveler theme < 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2025-09-26
CVE-2025-59011 WordPress Traveler Theme < 3.2.3 - Arbitrary Content Deletion Vulnerability CWE-862 7.5 High 2025-09-26
CVE-2025-52714 WordPress Traveler theme < 3.2.2 - SQL Injection Vulnerability CWE-89 9.3 Critical 2025-07-16
CVE-2025-26733 WordPress Traveler theme < 3.2.1 - Broken Access Control vulnerability CWE-862 8.2 High 2025-03-27
CVE-2025-26873 WordPress Traveler theme <= 3.1.8 - PHP Object Injection vulnerability CWE-502 9.0 Critical 2025-03-27
CVE-2025-26898 WordPress Traveler theme < 3.2.1 - SQL Injection vulnerability CWE-89 9.3 Critical 2025-03-27
CVE-2025-26956 WordPress Traveler theme < 3.2.1 - Broken Access Control vulnerability CWE-862 7.6 High 2025-03-27

All 18 known CVE vulnerabilities affecting Traveler with full Chinese analysis, references, and POCs where available.