CVE-2025-7575 | Zavy86 WikiDocs up to 1.0.77 submit.php image_drop_upload_ajax/image_delete_ajax path traversal (ID 258 / EUVD-2025-21309)
A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the file submit.php. The manipulation leads to path traversal.
This vulnerability is known as CVE-2025-7575. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.