All 4 CVE vulnerabilities found in Echo, with AI-generated Chinese analysis, references, and POCs.
Vendor: AncoraThemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55677 | Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files CWE-22 | 7.5 | High | 2026-06-26 |
| CVE-2026-5266 | Wikimedia Echo 信息泄露漏洞 CWE-200 | - | - | 2026-05-11 |
| CVE-2026-25766 | Echo has a Windows path traversal via backslash in middleware.Static default filesystem CWE-22 | 5.3 | Medium | 2026-02-19 |
| CVE-2025-53432 | WordPress Echo theme <= 1.15.0 - Local File Inclusion vulnerability CWE-98 | 8.1 | High | 2025-12-18 |
All 4 known CVE vulnerabilities affecting Echo with full Chinese analysis, references, and POCs where available.