Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 10.0
CVE-2026-61424

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-61900

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60032

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.6
CVE-2026-63429

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.4
CVE-2026-45797

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG fil…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-57311

Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Cod…

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-48062

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php check…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-36669

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious…

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 8.8
CVE-2026-13352

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-12684

The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.1
CVE-2026-50124

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Exc…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.8
CVE-2026-61457

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-11579

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing f…

Mitigation only
Fix from $1,600 2026-07-15
Commerce CRITICAL 9.3
CVE-2026-48356EPSS 28%

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the c…

Fix: 1.21.0+
Fix from $2,300 2026-07-14
Unclassified HIGH 7.3
CVE-2026-15677

A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-58409

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) …

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.8
CVE-2026-49972

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploadin…

Patch available
Fix from $1,950 2026-07-13
Firefox Mobile MEDIUM 5.3
CVE-2026-14906

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS applicatio…

Fix: 152.4+
Fix from $1,600 2026-07-13
Unclassified CRITICAL 9.9
CVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue…

No fix yet
Fix from $2,300 2026-07-13
Unclassified CRITICAL 10.0
CVE-2026-57719

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affec…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15553

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15488

A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller…

Patch available
Fix from $1,950 2026-07-12
Download HIGH 8.8
CVE-2026-57828

Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authe…

Fix: 6.1.3+
Fix from $1,950 2026-07-11
Rsfiles\! CRITICAL 9.8
CVE-2026-57827

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unaut…

Fix: 1.17.12+
Fix from $2,300 2026-07-11
Unclassified HIGH 8.8
CVE-2026-2354

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_exten…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified CRITICAL 9.8
CVE-2026-15282

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.2
CVE-2026-13430

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the im…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-14894

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 …

Patch available
Fix from $2,300 2026-07-10
Forms CRITICAL 9.8
CVE-2026-56291 KEVEPSS 76%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to…

Fix: 2.4.1+
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-15158

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen…

Mitigation only
Fix from $2,300 2026-07-09