high
CVE-2026-15450
NEX-Forms authenticated path traversal -> arbitrary file deletion
- Severity
- high
- Affected product
- nex-forms
- Affected versions
- nex-forms ≤ 9.1.6
- Fixed in
- nex-forms a release above 9.1.6
- Added to NewScan
- 2026-08-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints nex-forms from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →