← Vulnerability feed

Vulnerability record · CVE-2012-0896 · published 20 January 2012

CVE-2012-0896: Count per day project count per day path traversal vulnerability

CCount Per Day Project · Count Per Day

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

5.0 CVSS 2.0 Medium EPSS 23% · top 2.3% CWE-22 · Path traversal
5.0CVSS 2.0 base score
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-0896 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2015-5533Count per day project count per day sql injection vulnerabilitySQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators …EPSS 7.2%6.1CVE-2012-6714Count per day project count per day cross-site scripting vulnerabilityThe count-per-day plugin before 3.2.3 for WordPress has XSS via search words.EPSS 0.91%6.1CVE-2013-7472Count per day project count per day cross-site scripting vulnerabilityThe "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.EPSS 0.98%4.3CVE-2012-3434Tom braider count per day cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in userperspan.php in the Count Per Day module before 3.2 for WordPress allow remote attackers to…EPSS 2.4%4.3CVE-2012-0895Tom braider count per day cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in map/map.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to inject arbi…EPSS 5.3%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed

Source: NIST National Vulnerability Database (record CVE-2012-0896), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.