CVE Tools

Traveler

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Traveler, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Traveler CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Traveler CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-036
2025-042
2025-050
2025-060
2025-071
2025-080
2025-092
2025-100
2025-110
2025-124
2026-012
2026-020
2026-033
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical520%
  • High1040%
  • Medium936%
  • Low14%

Latest CVEs

The 15 most recently published vulnerabilities affecting Traveler.

  1. CVE-2026-56547An input reflection vulnerability affects HCL Traveler3.5
  2. CVE-2026-21790HCL Traveler is susceptible to a weak default HTTP header validation vulnerability6.3
  3. CVE-2026-21783HCL Traveler is affected by sensitive information disclosure4.3
  4. CVE-2026-25449WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability9.8
  5. CVE-2026-24367WordPress Traveler theme < 3.2.8 - SQL Injection vulnerability8.5
  6. CVE-2025-67917WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability6.5
  7. CVE-2025-64373WordPress Traveler theme < 3.2.6 - Local File Inclusion vulnerability8.1
  8. CVE-2025-64372WordPress Traveler theme < 3.2.6 - Cross Site Scripting (XSS) vulnerability7.1
  9. CVE-2025-64371WordPress Traveler theme < 3.2.6 - SQL Injection vulnerability8.5
  10. CVE-2025-63028WordPress Traveler theme <= 3.2.6 - Broken Access Control vulnerability5.3
  11. CVE-2025-59012WordPress Traveler theme < 3.2.3 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  12. CVE-2025-59011WordPress Traveler Theme < 3.2.3 - Arbitrary Content Deletion Vulnerability7.5
  13. CVE-2025-52714WordPress Traveler theme < 3.2.2 - SQL Injection Vulnerability9.3
  14. CVE-2025-0278An internal path disclosure vulnerability affects HCL Traveler4.3
  15. CVE-2025-0279HCL Traveler is affected by generation of error messages containing sensitive information4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store