tag
Cwe-434
Critical
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
CVE-2026-48939·
iCagenda — events/calendar extension (component) for Joomla
patched
Critical
WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170·
WP移行専用プラグイン for CPI (cpi-wp-migration, a CPI/site-migration import plugin for WordPress)
unpatched
Critical
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401·
WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla
unpatched
Critical
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
CVE-2025-6440·
WordPress WooCommerce Dynamic Pricing & Discounts plugin (wc-designer-pro)
unpatched
Critical
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009·
Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin)
patched
Critical
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
CVE-2025-7441·
StoryChief WordPress plugin
unpatched
Critical
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
CVE-2025-48148·
StoreKeeper for WooCommerce (WordPress plugin)
unpatched
Critical
SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)
CVE-2025-31324·
SAP NetWeaver Application Server (AS) Java — Visual Composer component (VCFRAMEWORK), specifically the Metadata Uploader servlet
patched
Critical
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
CVE-2025-4632·
Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet
unpatched
Critical
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147·
Podlove Podcast Publisher (WordPress plugin)
unpatched
Critical
Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)
CVE-2025-34299·
Monsta FTP (web-based FTP manager)
patched
Critical
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071·
Flozen Theme for WordPress
unpatched
Critical
Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595·
Cibeles AI (WordPress plugin)
unpatched
Critical
AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597·
AI Feeds (WordPress plugin)
unpatched
Critical
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
CVE-2025-54236·
Adobe Commerce / Magento Open Source — customer/address_file/upload endpoint (dubbed "SessionReaper")
patched
High
WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740
CVE-2026-0740·
WordPress "Ninja Forms" plugin — file upload field/module
unpatched
High
WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364·
WordPress plugin "Drag and Drop File Upload for Contact Form 7" (drag-and-drop-file-upload-for-contact-form-7)
unpatched
Critical
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555·
WebStack theme for WordPress
unpatched
High
Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748·
Visitor Management System (sanjay1313) 1.0
unpatched
Critical
Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
CVE-2026-37068·
Veno File Manager Project
unpatched
High
Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067·
Schema & Structured Data for WP & AMP (WordPress plugin, schema-and-structured-data-for-wp)
unpatched
Critical
midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306·
midi-Synth WordPress plugin
unpatched
High
Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911·
Hustle (wordpress-popup) plugin by WPMU DEV
unpatched
Medium
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657·
EventPrime (WordPress plugin)
patched
High
Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041·
Chamilo LMS
unpatched
Critical
BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960·
BookingPress Pro (WordPress appointment-booking plugin)
unpatched
High
Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099·
Bludit CMS (/api/files/<page-key> endpoint)
patched
Critical
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p)·
SP Page Builder extension for Joomla (joomshaper.net)
patched