<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Unrestricted File Upload (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/upload.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/upload-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Unrestricted File Upload (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2018-25412 – Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25412</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25412</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25412</strong></p>
  <p>Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25412">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25409 – SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25409</guid>
    <pubDate>Sat, 30 May 2026 16:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25409</strong></p>
  <p>SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25388 – HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25388</guid>
    <pubDate>Fri, 29 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25388</strong></p>
  <p>HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39292 – Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39292</guid>
    <pubDate>Fri, 29 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39292</strong></p>
  <p>Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exists due to insufficient validation of uploaded file types and executable content.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10072 – DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10072</guid>
    <pubDate>Fri, 29 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10072</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-10071 – DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10071</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-10071</strong></p>
  <p>DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30761 – An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php compo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30761</guid>
    <pubDate>Thu, 28 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30761</strong></p>
  <p>An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9227 – The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9227</guid>
    <pubDate>Thu, 28 May 2026 08:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9227</strong></p>
  <p>The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25353 – Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25353</guid>
    <pubDate>Sat, 23 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25353</strong></p>
  <p>Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6960 – The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file upload...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6960</guid>
    <pubDate>Thu, 21 May 2026 22:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6960</strong></p>
  <p>The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vuln…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6555 – The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6555</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6555</strong></p>
  <p>The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30117 – scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30117</guid>
    <pubDate>Tue, 19 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30117</strong></p>
  <p>scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted SVG file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4883 – The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4883</guid>
    <pubDate>Tue, 19 May 2026 13:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4883</strong></p>
  <p>The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4885 – The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4885</guid>
    <pubDate>Tue, 19 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4885</strong></p>
  <p>The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be upl…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25335 – WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25335</guid>
    <pubDate>Sun, 17 May 2026 13:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25335</strong></p>
  <p>WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37227 – HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37227</guid>
    <pubDate>Sat, 16 May 2026 16:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37227</strong></p>
  <p>HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47965 – WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47965</guid>
    <pubDate>Fri, 15 May 2026 19:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47965</strong></p>
  <p>WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation. Attackers can upload arbitrary files through the filemanager upload endpoint to achieve remote code execution and complete system compromise.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41937 – Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41937</guid>
    <pubDate>Thu, 14 May 2026 15:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41937</strong></p>
  <p>Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containing a plugin.php with a valid Slug header and a public/index.php file with arbitrary PHP code, which executes as the web server user once accessed via subsequent…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6271 – The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6271</guid>
    <pubDate>Thu, 14 May 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6271</strong></p>
  <p>The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45053 – CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45053</guid>
    <pubDate>Wed, 13 May 2026 21:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45053</strong></p>
  <p>CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the web-accessible images/source/ directory, where they are executed by the web server. Combined with a p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37430 – An arbitrary file upload vulnerability in the ShopOrderImportController.java com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37430</guid>
    <pubDate>Wed, 13 May 2026 14:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37430</strong></p>
  <p>An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27753 – An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27753</guid>
    <pubDate>Tue, 12 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27753</strong></p>
  <p>An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47940 – WordPress Plugin Download From Files version 1.48 and earlier contains an arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47940</guid>
    <pubDate>Sun, 10 May 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47940</strong></p>
  <p>WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the download_from_files_617_fileupload action, manipulating the allowExt parameter to bypass file type restriction…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-47933 – WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47933</guid>
    <pubDate>Sun, 10 May 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-47933</strong></p>
  <p>WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6692 – The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6692</guid>
    <pubDate>Thu, 07 May 2026 06:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6692</strong></p>
  <p>The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The v…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41938 – Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41938</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41938</strong></p>
  <p>Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map .phtml extensions to the PHP handler. Attackers can upload a .phtml file containing arbitrary PHP code and execute the uploaded payload through a subsequent un…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6261 – The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6261</guid>
    <pubDate>Tue, 05 May 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6261</strong></p>
  <p>The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38751 – OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38751</guid>
    <pubDate>Mon, 04 May 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38751</strong></p>
  <p>OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7490 – CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7490</guid>
    <pubDate>Sat, 02 May 2026 10:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7490</strong></p>
  <p>CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4882 – The User Registration Advanced Fields plugin for WordPress is vulnerable to arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4882</guid>
    <pubDate>Sat, 02 May 2026 05:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4882</strong></p>
  <p>The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerabi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-50993 – Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50993</guid>
    <pubDate>Thu, 30 Apr 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-50993</strong></p>
  <p>Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicious files by sending multipart POST requests with arbitrary filenames and disguised content types. Attackers can upload PHP webshells to the Document directory and execute them via HTTP GET requests to…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5364 – The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5364</guid>
    <pubDate>Fri, 24 Apr 2026 06:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5364</strong></p>
  <p>The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and allowing the file type parameter to be controlled by the attacker rather than being restricted to administrator-configured values, which when combined with the fa…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6885 – Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6885</guid>
    <pubDate>Thu, 23 Apr 2026 10:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6885</strong></p>
  <p>Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3844 – The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3844</guid>
    <pubDate>Thu, 23 Apr 2026 03:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3844</strong></p>
  <p>The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37748 – Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37748</guid>
    <pubDate>Tue, 21 Apr 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37748</strong></p>
  <p>Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP webshell and achieve Remote Code Execution on the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6518 – The CMP – Coming Soon &amp; Maintenance Plugin by NiteoThemes plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6518</guid>
    <pubDate>Sat, 18 Apr 2026 05:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6518</strong></p>
  <p>The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability (available to Editors and above) instead of `manage_options` (Administrators only), c…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5718 – The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5718</guid>
    <pubDate>Fri, 17 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5718</strong></p>
  <p>The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1555 – The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1555</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1555</guid>
    <pubDate>Wed, 15 Apr 2026 04:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1555</strong></p>
  <p>The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1555">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38526 – An authenticated arbitrary file upload vulnerability in the /admin/tinymce/uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38526</guid>
    <pubDate>Tue, 14 Apr 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38526</strong></p>
  <p>An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-51414 – In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-51414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-51414</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-51414</strong></p>
  <p>In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-51414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40040 – Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40040</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40040</strong></p>
  <p>Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files .php5 scripts to web-accessible directories and execute them to achieve remote code execution on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32931 – Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32931</guid>
    <pubDate>Fri, 10 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32931</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded file retains its original .php extension and is placed in a web-accessible directory, enabling Remote Code Execution as…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1830 – The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1830</guid>
    <pubDate>Thu, 09 Apr 2026 05:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1830</strong></p>
  <p>The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code ex…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-2942 – The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2942</guid>
    <pubDate>Wed, 08 Apr 2026 19:25:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-2942</strong></p>
  <p>The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4808 – The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4808</guid>
    <pubDate>Wed, 08 Apr 2026 07:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4808</strong></p>
  <p>The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUploadedFile() function in all versions up to, and including, 1.3.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execut…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3535 – The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3535</guid>
    <pubDate>Wed, 08 Apr 2026 07:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3535</strong></p>
  <p>The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a user-supplied URL as a CSS file, extracts URLs from its content, and downloads those…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-0740 – The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0740</guid>
    <pubDate>Tue, 07 Apr 2026 05:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-0740</strong></p>
  <p>The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note:…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35164 – Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35164</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35164</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirely on user input. This allows an authenticated user to upload executable PHP scripts and gain Remote…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35047 – Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35047</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35047</strong></p>
  <p>Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, data exfiltration, or service disruption. All users running affected versions of BraveCMS are impact…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25685 – phpBB contains an arbitrary file upload vulnerability that allows authenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25685</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25685</strong></p>
  <p>phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25673 – UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25673</guid>
    <pubDate>Sun, 05 Apr 2026 21:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25673</strong></p>
  <p>UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-20052 – Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20052</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-20052</strong></p>
  <p>Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded file path to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4809 – plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4809</guid>
    <pubDate>Thu, 26 Mar 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4809</strong></p>
  <p>plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25630 – PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Imag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25630</guid>
    <pubDate>Tue, 24 Mar 2026 12:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25630</strong></p>
  <p>PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60947 – Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60947</guid>
    <pubDate>Mon, 23 Mar 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60947</strong></p>
  <p>Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33072 – FileRise is a self-hosted web file manager / WebDAV server. In versions prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33072</guid>
    <pubDate>Fri, 20 Mar 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33072</strong></p>
  <p>FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptographic operations — HMAC token generation, AES config encryption, and session tokens — allowing any unauthenticated attacker to forge upload tokens for arbitrary file upload to shared folders, and to decrypt admin config…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32985 – Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32985</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32985</strong></p>
  <p>Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads. Attackers can bypass authentication checks in the import.php file to upload a template archive with PHP code in the media dire…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32756 – Admidio is an open-source user management solution. Versions 5.0.6 and below con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32756</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32756</strong></p>
  <p>Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an authenticated user with upload permissions can bypass file extension restrictions by intentionally submitti…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29859 – An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29859</guid>
    <pubDate>Wed, 18 Mar 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29859</strong></p>
  <p>An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30875 – Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30875</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30875</strong></p>
  <p>Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .htaccess or PHP files with alternative extensions. An attacker uploads a crafted H5P package containi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-20224 – Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-20224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-20224</guid>
    <pubDate>Mon, 16 Mar 2026 14:17:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-20224</strong></p>
  <p>Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable code, delete files, or manipulate server content for remote code execution or denial of service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-20224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3891 – The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file upl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3891</guid>
    <pubDate>Fri, 13 Mar 2026 19:55:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3891</strong></p>
  <p>The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25480 – ARMBot contains an unrestricted file upload vulnerability in upload.php that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25480</guid>
    <pubDate>Wed, 11 Mar 2026 19:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25480</strong></p>
  <p>ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-25471 – FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25471</guid>
    <pubDate>Wed, 11 Mar 2026 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-25471</strong></p>
  <p>FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary commands through the extracted PHP files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13067 – The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13067</guid>
    <pubDate>Wed, 11 Mar 2026 05:17:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13067</strong></p>
  <p>The Royal Addons for Elementor plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 1.7.1049. This is due to insufficient file type validation detecting files named main.php, allowing a file with such a name to bypass sanitization. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25737 – Budibase is a low code platform for creating internal tools, workflows, and admi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25737</guid>
    <pubDate>Mon, 09 Mar 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25737</strong></p>
  <p>Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. The restriction is enforced only at the UI level. An attacker can bypass these restrictions and upload malicious files.</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3459 – The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3459</guid>
    <pubDate>Thu, 05 Mar 2026 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3459</strong></p>
  <p>The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Th…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63910 – An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63910</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63910</strong></p>
  <p>An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1565 – The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Members...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1565</guid>
    <pubDate>Thu, 26 Feb 2026 20:31:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1565</strong></p>
  <p>The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4.2.8. This makes it possible for auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25158 – Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25158</guid>
    <pubDate>Fri, 20 Feb 2026 23:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25158</strong></p>
  <p>Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing the uploaded files.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1405 – The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1405</guid>
    <pubDate>Thu, 19 Feb 2026 07:17:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1405</strong></p>
  <p>The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70151 – code-projects Scholars Tracking System 1.0 allows an authenticated attacker to a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70151</guid>
    <pubDate>Wed, 18 Feb 2026 18:24:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70151</strong></p>
  <p>code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13689 – IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13689</guid>
    <pubDate>Tue, 17 Feb 2026 23:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13689</strong></p>
  <p>IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1306 – The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1306</guid>
    <pubDate>Sat, 14 Feb 2026 07:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1306</strong></p>
  <p>The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible granted the attacker can obtain a valid…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1357 – The Migration, Backup, Staging – WPvivid Backup &amp; Migration plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1357</guid>
    <pubDate>Wed, 11 Feb 2026 06:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1357</strong></p>
  <p>The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writing uploaded files. When the plugin fails to decrypt a session key using openssl_private_decrypt(), it…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2097 – Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2097</guid>
    <pubDate>Tue, 10 Feb 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2097</strong></p>
  <p>Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1499 – The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization lea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1499</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1499</guid>
    <pubDate>Fri, 06 Feb 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1499</strong></p>
  <p>The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file upload functionality. This makes it possible for authenticated (subscriber-level) attackers to set the internal `prod_key_r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1499">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69906 – Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69906</guid>
    <pubDate>Thu, 05 Feb 2026 17:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69906</strong></p>
  <p>Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upload files that are interpreted as executable code, resulting in remote code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1756 – The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1756</guid>
    <pubDate>Wed, 04 Feb 2026 07:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1756</strong></p>
  <p>The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WP_FOFT_Loader_Mimes::file_and_ext' function in all versions up to, and including, 2.1.39. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution p…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69981 – FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/uplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69981</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69981</strong></p>
  <p>FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65875 – An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65875</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65875</strong></p>
  <p>An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1730 – The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1730</guid>
    <pubDate>Tue, 03 Feb 2026 08:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1730</strong></p>
  <p>The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execut…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-57794 – Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57794</guid>
    <pubDate>Wed, 28 Jan 2026 18:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-57794</strong></p>
  <p>Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1400 – The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1400</guid>
    <pubDate>Wed, 28 Jan 2026 09:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1400</strong></p>
  <p>The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3.3.2. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server w…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0911 – The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0911</guid>
    <pubDate>Sat, 24 Jan 2026 13:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0911</strong></p>
  <p>The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7.8.9.2. This makes it possible for authenticated attackers, with a lower-privileged role (e.g., Subscriber-level access and above), to upload arbitrary files on…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-13374 – The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13374</guid>
    <pubDate>Sat, 24 Jan 2026 08:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-13374</strong></p>
  <p>The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1331 – MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1331</guid>
    <pubDate>Thu, 22 Jan 2026 09:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1331</strong></p>
  <p>MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1222 – PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1222</guid>
    <pubDate>Tue, 20 Jan 2026 07:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1222</strong></p>
  <p>PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-10064 – Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file uplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-10064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-10064</guid>
    <pubDate>Fri, 16 Jan 2026 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-10064</strong></p>
  <p>Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to place attacker-controlled files under the plugin's uploads directory. This can…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-10064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12957 – The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12957</guid>
    <pubDate>Fri, 16 Jan 2026 05:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12957</strong></p>
  <p>The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.5.7. This is due to insufficient file type validation detecting VTT files, allowing double extension files to bypass sanitization while being accepted as a valid VTT file. This makes it possible for authenticated attackers, with author-level access and above, to upload…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-1021 – Police Statistics Database System developed by Gotac has an Arbitrary File Uploa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1021</guid>
    <pubDate>Fri, 16 Jan 2026 03:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-1021</strong></p>
  <p>Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-10041 – Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-10041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-10041</guid>
    <pubDate>Thu, 15 Jan 2026 22:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-10041</strong></p>
  <p>Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution by uploading executable content to a web-accessible location.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-10041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13062 – The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13062</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13062</strong></p>
  <p>The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-37175 – Arbitrary file upload vulnerability exists in the web-based management interface...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37175</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-37175</strong></p>
  <p>Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-65783 – An arbitrary file upload vulnerability in the /utils/uploadFile component of Hub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65783</guid>
    <pubDate>Tue, 13 Jan 2026 16:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65783</strong></p>
  <p>An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67325 – Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67325</guid>
    <pubDate>Thu, 08 Jan 2026 19:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67325</strong></p>
  <p>Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22241 – The Open eClass platform (formerly known as GUnet eClass) is a complete course m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22241</guid>
    <pubDate>Thu, 08 Jan 2026 15:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22241</strong></p>
  <p>The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vulnerability in the theme import functionality enables an attacker with administrative privileges to upload arbitrary files on the server's file system. The main cause of the issue is that no validation or sanitization of the file's present inside the z…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-25296 – The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25296</guid>
    <pubDate>Thu, 08 Jan 2026 03:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-25296</strong></p>
  <p>The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. Additionally, t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15158 – The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15158</guid>
    <pubDate>Wed, 07 Jan 2026 12:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15158</strong></p>
  <p>The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15240 – QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15240</guid>
    <pubDate>Mon, 05 Jan 2026 09:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15240</strong></p>
  <p>QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15240">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
