CVE-2026-19229CWE-200CWE-538information-disclosure

CVE-2026-19229

Medium · published August 7, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
25.6
In the wild
Unconfirmed
What it is

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00329 · 25.6th percentile
Weaknesses
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor; CWE-538 · Insertion of Sensitive Information into Externally-Accessible File or Directory
Published
2026-08-07T22:17Z
References (6)
EPSS history
Timeline
  • 07 AUG 18:00Z
    SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
    cvelistv5