<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Robo (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/robo.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/robo-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Robo (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:57 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-14306 – A directory traversal vulnerability exists in the CacheCleaner component of Robo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14306</guid>
    <pubDate>Tue, 09 Dec 2025 16:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14306</strong></p>
  <p>A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to traverse directories and delete arbitrary files on the system. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the file path, leading to potential unauthorized file…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54392 – Cross-Site Request Forgery (CSRF) vulnerability in midoks WP微信机器人 wp-weixin-robo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54392</guid>
    <pubDate>Mon, 16 Dec 2024 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54392</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in midoks WP微信机器人 wp-weixin-robot allows Stored XSS.This issue affects WP微信机器人: from n/a through <= 5.3.5.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2010-4095 – Directory traversal vulnerability in the FTP client in Serengeti Systems Incorpo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4095</guid>
    <pubDate>Tue, 26 Oct 2010 20:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2010-4095</strong></p>
  <p>Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a filename in a server response.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-4103 – Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4103</guid>
    <pubDate>Sun, 29 Nov 2009 13:08:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-4103</strong></p>
  <p>Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service and possibly execute arbitrary code via unspecified FTP server responses.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-3068 – Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3068</guid>
    <pubDate>Fri, 04 Sep 2009 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-3068</strong></p>
  <p>Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3068">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
