PoC Archive PoC Archive

tag

Arbitrary-File-Upload

Critical
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401· WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla unpatched
Critical
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057· WavePlayer (WordPress plugin) unpatched
Critical
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
CVE-2025-7441· StoryChief WordPress plugin unpatched
Critical
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
CVE-2025-48148· StoreKeeper for WooCommerce (WordPress plugin) unpatched
Critical
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
CVE-2025-4632· Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet unpatched
Critical
KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674· KiotViet Sync (WordPress plugin) unpatched
Critical
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071· Flozen Theme for WordPress unpatched
Critical
WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
CVE-2026-1357· WPvivid Backup & Migration WordPress plugin unpatched
Critical
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555· WebStack theme for WordPress unpatched
Critical
Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627· plg_system_nrframework (Tassos/Novarain Framework) Joomla plugin, bundled with Convert Forms, Engage Box, Google Structured Data, and other Tassos.gr extensions patched
Medium
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657· EventPrime (WordPress plugin) patched