Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
Unclassified CRITICAL 9.9
CVE-2026-56058

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 10.0
CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n…

Mitigation only
Fix from $2,300 2026-06-25
K2 MEDIUM 5.3
CVE-2026-48945

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jp…

Fix: after 2.26
Fix from $1,600 2026-06-25
K2 MEDIUM 6.3
CVE-2026-48946

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes t…

Fix: after 2.26
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.4
CVE-2026-53948

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin …

Mitigation only
Fix from $1,600 2026-06-24
Sp Page Builder CRITICAL 9.8
CVE-2026-48908 KEVEPSS 88%

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio…

Fix: 6.6.2+
Fix from $2,300 2026-06-20
Icagenda CRITICAL 9.8
CVE-2026-48939 KEVEPSS 83%

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP…

Fix: 3.9.15 / 4.0.8+
Fix from $2,300 2026-06-20
Vbizz HIGH 8.8
CVE-2019-25758

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by…

No fix yet
Fix from $1,950 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr…

No fix yet
Fix from $2,300 2026-06-19
Unclassified HIGH 8.8
CVE-2026-9860

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.0
CVE-2026-52705

Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40746

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40747

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40748

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40749

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified HIGH 8.0
CVE-2026-39598

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue a…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-39589

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-27041

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-25446

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-22327

Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 10.0
CVE-2025-69129

Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.

Mitigation only
Fix from $2,300 2026-06-17
Zie For Web CRITICAL 9.8
CVE-2025-59872

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obt…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2025-60218

Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2024-52488

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40750

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This is…

Mitigation only
Fix from $2,300 2026-06-16
Unclassified HIGH 8.8
CVE-2026-6933

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. Th…

Mitigation only
Fix from $1,950 2026-06-16
Unclassified CRITICAL 10.0
CVE-2026-40772

Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.9
CVE-2026-39591

Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

Mitigation only
Fix from $2,300 2026-06-15