CyberRota Analysis
AI-GeneratedVavo Core versions up to 2.3.0 are vulnerable to unauthenticated local file inclusion, allowing attackers to access sensitive files on the server. This could lead to data exposure or further exploitation of the system. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.
CVE
CVE-2026-28570
Severity
HIGH
CVSS
8.1
EPSS
0.27%
Original NVD Description
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.