PoC Archive PoC Archive

tag

Cwe-434

Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CVE-2025-11170webCRITICAL 9.8Unpatched2026-07-06WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CVE-2025-6440webCRITICAL 9.8Unverified2026-07-06Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CVE-2025-29009webCRITICAL 10Patched2026-07-06StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CVE-2025-7441webCRITICAL 9.8Unpatched2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324) KEV RW EPSS 100%
CVE-2025-31324 web Patched
CVE-2025-31324webCRITICAL 10Patched2026-07-06Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632) KEV EPSS 24%
CVE-2025-4632 web Patched
CVE-2025-4632webCRITICAL 9.8Patched2026-07-06Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CVE-2025-10147webCRITICAL 9.8Unverified2026-07-06Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CVE-2025-13595webCRITICAL 9.8Unverified2026-07-06AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CVE-2025-13597webCRITICAL 9.8Unverified2026-07-06Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236) KEV EPSS 95%
CVE-2025-54236 web Patched
CVE-2025-54236webCRITICAL 9.1Patched2026-07-06WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
CVE-2026-0740webHIGHUnverified2026-07-05WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
CVE-2026-5364webHIGH 8.1Unverified2026-07-05WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CVE-2026-1555webCRITICAL 9.8Unverified2026-07-05Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
CVE-2026-37748webHIGH 7.2Unverified2026-07-05Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068 web Unverified
CVE-2026-37068webCRITICALUnverified2026-07-05Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067 web Unverified
CVE-2026-9067webHIGH 8.1Unverified2026-07-05midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CVE-2026-1306webCRITICAL 9.8Unverified2026-07-05Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
CVE-2026-0911webHIGHUnverified2026-07-05EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657 web Patched
CVE-2026-1657webMEDIUMPatched2026-07-05Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
CVE-2026-29041webHIGH 8.8Patched2026-07-05BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CVE-2026-6960webCRITICAL 9.8Unverified2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30