Vulnerability index

Browse CVEs

4,166 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Unrestricted File UploadCWE-434 × clear
CRITICAL 9.9 CVE-2026-56058 Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56059 Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56027 Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 10.0 CVE-2026-57700 Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n… Mitigation only Fix from $2,3002026-06-25 MEDIUM 5.3 CVE-2026-48945 The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jp… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 6.3 CVE-2026-48946 The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes t… K2 after 2.26 Fix from $1,6002026-06-25 MEDIUM 5.4 CVE-2026-53948 Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin … Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.8 CVE-2026-48908 KEVEPSS 88% A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio… Sp Page Builder 6.6.2+ Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-48939 KEVEPSS 83% A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Icagenda 3.9.15 / 4.0.8+ Fix from $2,3002026-06-20 HIGH 8.8 CVE-2019-25758 Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by… Vbizz No fix yet Fix from $1,9502026-06-19 CRITICAL 9.8 CVE-2026-54414 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr… No fix yet Fix from $2,3002026-06-19 HIGH 8.8 CVE-2026-9860 The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… Mitigation only Fix from $1,9502026-06-18 CRITICAL 9.0 CVE-2026-52705 Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40746 Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40747 Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40748 Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40749 Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. Mitigation only Fix from $2,3002026-06-17 HIGH 8.0 CVE-2026-39598 Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue a… Mitigation only Fix from $1,9502026-06-17 CRITICAL 9.9 CVE-2026-39589 Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-27041 Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-25446 Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-22327 Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2025-69129 Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-59872 HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obt… Zie For Web Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2025-60218 Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2024-52488 Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40750 Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This is… Mitigation only Fix from $2,3002026-06-16 HIGH 8.8 CVE-2026-6933 The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. Th… Mitigation only Fix from $1,9502026-06-16 CRITICAL 10.0 CVE-2026-40772 Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.9 CVE-2026-39591 Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. Mitigation only Fix from $2,3002026-06-15