Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 10.0 CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln… No fix yet Fix from $2,3002026-07-20 CRITICAL 10.0 CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic… No fix yet Fix from $2,3002026-07-20 HIGH 8.6 CVE-2026-63429 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.4 CVE-2026-45797 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG fil… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-57311 Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Cod… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.8 CVE-2026-48062 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php check… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-36669 An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious… No fix yet Fix from $2,3002026-07-17 HIGH 8.8 CVE-2026-13352 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-12684 The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media… No fix yet Fix from $1,6002026-07-16 HIGH 7.1 CVE-2026-50124 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Exc… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-61457 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.3 CVE-2026-11579 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing f… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.3 CVE-2026-48356EPSS 28% Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the c… Commerce 1.21.0+ Fix from $2,3002026-07-14 HIGH 7.3 CVE-2026-15677 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a… Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-58409 ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) … Mitigation only Fix from $2,3002026-07-13 HIGH 8.8 CVE-2026-49972 Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploadin… Patch available Fix from $1,9502026-07-13 MEDIUM 5.3 CVE-2026-14906 Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS applicatio… Firefox Mobile 152.4+ Fix from $1,6002026-07-13 CRITICAL 9.9 CVE-2026-57710 Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue… No fix yet Fix from $2,3002026-07-13 CRITICAL 10.0 CVE-2026-57719 Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affec… Mitigation only Fix from $2,3002026-07-13 MEDIUM 5.3 CVE-2026-15553 Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious… Mitigation only Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15488 A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller… Patch available Fix from $1,9502026-07-12 HIGH 8.8 CVE-2026-57828 Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authe… Download 6.1.3+ Fix from $1,9502026-07-11 CRITICAL 9.8 CVE-2026-57827 Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unaut… Rsfiles\! 1.17.12+ Fix from $2,3002026-07-11 HIGH 8.8 CVE-2026-2354 The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_exten… Mitigation only Fix from $1,9502026-07-11 CRITICAL 9.8 CVE-2026-15282 The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_… Mitigation only Fix from $2,3002026-07-10 HIGH 7.2 CVE-2026-13430 The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the im… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-14894 The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 … Patch available Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-56291 KEVEPSS 76% Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… Forms 2.4.1+ Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-15158 The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen… Mitigation only Fix from $2,3002026-07-09