Total
3867 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-30510 | 1 Salonbookingsystem | 1 Salon Booking System | 2025-02-27 | N/A | 10.0 CRITICAL |
|
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
|
|||||
| CVE-2024-5084 | 1 Hashthemes | 1 Hash Form | 2025-02-27 | N/A | 9.8 CRITICAL |
|
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
|
|||||
| CVE-2024-8066 | 1 Ninjateam | 1 Filester | 2025-02-26 | N/A | 7.5 HIGH |
|
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a new .htaccess file allowing them to subsequently upload arbitrary files on the affected site's server which may make remote code execution possible.
|
|||||
| CVE-2023-28725 | 1 Generalbytes | 1 Crypto Application Server | 2025-02-26 | N/A | 9.1 CRITICAL |
|
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
|
|||||
| CVE-2024-2394 | 1 Walterjnr1 | 1 Employee Management System | 2025-02-26 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/add-admin.php. The manipulation of the argument avatar leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256454 is the identifier assigned to this vulnerability.
|
|||||
| CVE-2024-1527 | 1 Cmsmadesimple | 1 Cms Made Simple | 2025-02-26 | N/A | 9.8 CRITICAL |
|
Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.
|
|||||
| CVE-2023-6090 | 1 Mollie | 1 Mollie Payments For Woocommerce | 2025-02-26 | N/A | 9.1 CRITICAL |
|
Unrestricted Upload of File with Dangerous Type vulnerability in Mollie Mollie Payments for WooCommerce.This issue affects Mollie Payments for WooCommerce: from n/a through 7.3.11.
|
|||||
| CVE-2025-0731 | 2025-02-26 | N/A | 6.5 MEDIUM | ||
|
An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.
|
|||||
| CVE-2020-19786 | 1 Cszcms | 1 Csz Cms | 2025-02-25 | N/A | 8.8 HIGH |
|
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
|
|||||
| CVE-2025-0722 | 1 Needyamin | 1 Image Gallery Management System | 2025-02-25 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2024-13365 | 1 Cleantalk | 1 Security \& Malware Scan | 2025-02-25 | N/A | 9.8 CRITICAL |
|
The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin uploading and extracting .zip archives when scanning them for malware through the checkUploadedArchive() function in all versions up to, and including, 2.149. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
|
|||||
| CVE-2024-29135 | 1 Themefic | 1 Tourfic | 2025-02-25 | N/A | 9.9 CRITICAL |
|
Unrestricted Upload of File with Dangerous Type vulnerability in Tourfic.This issue affects Tourfic: from n/a through 2.11.15.
|
|||||
| CVE-2025-1646 | 2025-02-25 | 7.5 HIGH | 7.3 HIGH | ||
|
A vulnerability, which was classified as critical, has been found in Lumsoft ERP 8. Affected by this issue is some unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx of the component ASPX File Handler. The manipulation of the argument file leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-1128 | 2025-02-25 | N/A | 9.8 CRITICAL | ||
|
The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensiti ...
Show More |
|||||
| CVE-2025-1355 | 1 Needyamin | 1 Library Card System | 2025-02-25 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signup.php of the component Add Picture. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-1590 | 2025-02-23 | 5.8 MEDIUM | 4.7 MEDIUM | ||
|
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
|
|||||
| CVE-2025-26776 | 2025-02-22 | N/A | 10.0 CRITICAL | ||
|
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.
|
|||||
| CVE-2022-34154 | 1 Ideastocode | 1 Enable Svg\, Webp \& Ico Upload | 2025-02-20 | N/A | 7.2 HIGH |
|
Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress.
|
|||||
| CVE-2022-28700 | 1 Givewp | 1 Givewp | 2025-02-20 | N/A | 9.1 CRITICAL |
|
Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
|
|||||
| CVE-2022-40217 | 1 Xplodedthemes | 1 Wpide | 2025-02-20 | N/A | 6.5 MEDIUM |
|
Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
|
|||||
| CVE-2022-40200 | 1 Gvectors | 1 Wpforo Forum | 2025-02-20 | N/A | 9.9 CRITICAL |
|
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
|
|||||
| CVE-2022-36386 | 1 Soflyy | 1 Wp All Import | 2025-02-20 | N/A | 9.1 CRITICAL |
|
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
|
|||||
| CVE-2024-4681 | 1 Campcodes | 1 Legal Case Management System | 2025-02-20 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability.
|
|||||
| CVE-2023-40219 | 1 Welcart | 1 Welcart E-commerce | 2025-02-20 | N/A | 7.2 HIGH |
|
Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory.
|
|||||
| CVE-2024-10960 | 1 Brizy | 1 Brizy | 2025-02-20 | N/A | 9.9 CRITICAL |
|
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
|
|||||
| CVE-2024-13544 | 1 Amini7 | 1 Zarinpal Paid Download | 2025-02-20 | N/A | 4.8 MEDIUM |
|
The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
|
|||||
| CVE-2021-44967 | 1 Limesurvey | 1 Limesurvey | 2025-02-20 | 9.0 HIGH | 8.8 HIGH |
|
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.
|
|||||
| CVE-2024-57407 | 2025-02-19 | N/A | 7.3 HIGH | ||
|
An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.
|
|||||
| CVE-2023-25828 | 1 Pluck-cms | 1 Pluck | 2025-02-19 | N/A | 7.2 HIGH |
|
Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it dire ...
Show More |
|||||
| CVE-2023-27246 | 1 Mk-auth | 1 Mk-auth | 2025-02-18 | N/A | 8.8 HIGH |
|
An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file.
|
|||||
| CVE-2025-22654 | 2025-02-18 | N/A | 10.0 CRITICAL | ||
|
Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified allows Using Malicious Files. This issue affects Simplified: from n/a through 1.0.6.
|
|||||
| CVE-2025-1165 | 2025-02-18 | 7.5 HIGH | 7.3 HIGH | ||
|
A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2021-3267 | 1 Kitesky | 1 Kitecms | 2025-02-18 | N/A | 7.2 HIGH |
|
File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.
|
|||||
| CVE-2023-26968 | 1 Atrocore | 1 Atrocore | 2025-02-18 | N/A | 9.8 CRITICAL |
|
In Atrocore 1.5.25, the Create Import Feed option with glyphicon-glyphicon-paperclip function is vulnerable to Unauthenticated File upload.
|
|||||
| CVE-2023-26830 | 1 Gladinet | 1 Centrestack | 2025-02-18 | N/A | 7.2 HIGH |
|
An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server.
|
|||||
| CVE-2021-31707 | 1 Kitesky | 1 Kitecms | 2025-02-18 | N/A | 9.8 CRITICAL |
|
Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.
|
|||||
| CVE-2024-2930 | 1 Oretnom23 | 1 Music Gallery Site | 2025-02-18 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=save_music. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258001 was assigned to this vulnerability.
|
|||||
| CVE-2024-2849 | 1 Ganeshrkt | 1 Simple File Manager Web App | 2025-02-18 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects unknown code. The manipulation of the argument photo leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257770 is the identifier assigned to this vulnerability.
|
|||||
| CVE-2024-2754 | 1 Donbermoy | 1 Complete E-commerce Site | 2025-02-18 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257544.
|
|||||
| CVE-2024-2690 | 1 Razormist | 1 Online Discussion Forum Site | 2025-02-18 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file /uupdate.php. The manipulation of the argument ima leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257388.
|
|||||