Total
4396 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-56058 | 2026-06-26 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | |||||
| CVE-2026-57658 | 2026-06-26 | N/A | 9.1 CRITICAL | ||
| Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. | |||||
| CVE-2026-56059 | 2026-06-26 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | |||||
| CVE-2026-56027 | 2026-06-26 | N/A | 9.9 CRITICAL | ||
| Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | |||||
| CVE-2025-59872 | 1 Hcltech | 1 Zie For Web | 2026-06-26 | N/A | 4.3 MEDIUM |
| HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code | |||||
| CVE-2019-19576 | 2 Joomlaworks, Verot Project | 2 K2, Verot | 2026-06-26 | 7.5 HIGH | 9.8 CRITICAL |
| class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions. | |||||
| CVE-2019-19634 | 2 Joomlaworks, Verot Project | 2 K2, Verot | 2026-06-26 | 7.5 HIGH | 9.8 CRITICAL |
| class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576. | |||||
| CVE-2026-53948 | 2026-06-25 | N/A | 5.4 MEDIUM | ||
| Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. This vulnerability is fixed in 6.21.1. | |||||
| CVE-2022-2356 | 1 Mediajedi | 1 User Private Files | 2026-06-23 | N/A | 8.8 HIGH |
| The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded. | |||||
| CVE-2024-25674 | 1 Misp-project | 1 Misp | 2026-06-22 | N/A | 9.8 CRITICAL |
| An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type. | |||||
| CVE-2024-29859 | 1 Misp-project | 1 Misp | 2026-06-22 | N/A | 9.8 CRITICAL |
| In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload. | |||||
| CVE-2026-9860 | 2026-06-18 | N/A | 8.8 HIGH | ||
| The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() does not strip single quotes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing — allowing a single quote in the account-id or api-key parameter to break out of the single-quoted PHP string literal in the write_config() define() statement. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. This is possible because the 'cf-images-nonce' nonce required by the AJAX handler is exposed to all Author-level and above users on wp-admin/upload.php via the CFImages JavaScript object, meaning any upload-capable user can satisfy the nonce check and reach the vulnerable wp-config.php write path. | |||||
| CVE-2025-13590 | 1 Wso2 | 4 Api Control Plane, Api Manager, Traffic Manager and 1 more | 2026-06-18 | N/A | 9.1 CRITICAL |
| A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload. | |||||
| CVE-2026-52705 | 2026-06-17 | N/A | 9.0 CRITICAL | ||
| Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | |||||
| CVE-2026-40748 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | |||||
| CVE-2026-40746 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | |||||
| CVE-2026-25446 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | |||||
| CVE-2025-69129 | 2026-06-17 | N/A | 10.0 CRITICAL | ||
| Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | |||||
| CVE-2025-60218 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | |||||
| CVE-2024-52488 | 2026-06-17 | N/A | 9.9 CRITICAL | ||
| Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. | |||||
