PoC Archive PoC Archive

tag

File Upload

WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291) KEV EPSS 15%
CVE-2026-56291 web Unverified
CVE-2026-56291webCRITICAL 9.8Unverified2026-07-27Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CVE-2025-6440webCRITICAL 9.8Unverified2026-07-06Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 web Patched
CVE-2025-27515webCRITICAL 9.8Patched2026-07-06Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236) KEV EPSS 95%
CVE-2025-54236 web Patched
CVE-2025-54236webCRITICAL 9.1Patched2026-07-06WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
CVE-2026-0740webHIGHUnverified2026-07-05WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CVE-2026-3844webCRITICALUnverified2026-07-05WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
CVE-2026-5364webHIGH 8.1Unverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
CVE-2026-5615 web Patched
CVE-2026-5615webHIGH 8.5Patched2026-07-05User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CVE-2026-4882webCRITICAL 9.8Unverified2026-07-05TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
CVE-2026-27621 (GHSA-xfvg-8v67-j7wp) web Patched
CVE-2026-27621webMEDIUMPatched2026-07-05Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
CVE-2026-40487 / GHSA-44wg-r34q-hvfx web Patched
CVE-2026-40487 / GHSA-44wg-r34q-hvfxwebHIGH 8.9Patched2026-07-05Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CVE-2026-4885webCRITICALUnverified2026-07-05Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
CVE-2026-3304 web Patched
CVE-2026-3304webHIGH 8.7Patched2026-07-05midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CVE-2026-1306webCRITICAL 9.8Unverified2026-07-05Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290 KEV EPSS 30%
CVE-2026-56290 web Patched
CVE-2026-56290webCRITICAL 9.8Patched2026-07-05Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
CVE-2026-0911webHIGHUnverified2026-07-05Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)) web Unverified
CVE-2026-54337webINFOUnverified2026-07-05EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
CVE-2026-33534 web Patched
CVE-2026-33534webMEDIUMPatched2026-07-05Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
CVE-2026-33033 web Patched
CVE-2026-33033webMEDIUMPatched2026-07-05Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
CVE-2026-29041 web Patched
CVE-2026-29041webHIGH 8.8Patched2026-07-05BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CVE-2026-6960webCRITICAL 9.8Unverified2026-07-05BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
CVE-2026-39387webHIGHPatched2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 (GHSA-gvq6-hvvp-h34h) web Patched
CVE-2026-21440webCRITICAL 9.2Patched2026-07-05Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245) KEV EPSS 25%
CVE-2026-20245 network Unpatched
CVE-2026-20245networkHIGH 7.8Unpatched2026-06-28