<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>File-Upload — PoC Archive</title><link>https://poc.intelseclab.com/tags/file-upload/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/file-upload/index.xml" rel="self" type="application/rss+xml"/><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>WooCommerce Dynamic Pricing &amp; Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6440. Status: Weaponized. Affects: WordPress WooCommerce Dynamic Pricing &amp; Discounts plugin (wc-designer-pro). Tags: wordpress, woocommerce, wc-designer-pro, dynamic-pricing, file-upload, rce, unauthenticated, wp-ajax, cwe-434, nuclei.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>wc-designer-pro</category><category>dynamic-pricing</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>wp-ajax</category><category>cwe-434</category><category>nuclei</category></item><item><title>Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-27515-laravel-polyglot-upload-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-27515-laravel-polyglot-upload-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-27515. Status: Weaponized. Affects: Laravel Framework (file upload validation using files.* wildcard rules). Tags: laravel, php, file-upload, validation-bypass, polyglot, jpeg, wildcard-validation, cwe-20, rce, web-shell.</description><category>web</category><category>Critical</category><category>laravel</category><category>php</category><category>file-upload</category><category>validation-bypass</category><category>polyglot</category><category>jpeg</category><category>wildcard-validation</category><category>cwe-20</category><category>rce</category><category>web-shell</category></item><item><title>Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-54236. Status: PoC. Affects: Adobe Commerce / Magento Open Source — customer/address_file/upload endpoint (dubbed "SessionReaper"). Tags: magento, adobe-commerce, sessionreaper, file-upload, lfi, customer-address, form-key, cwe-434, python.</description><category>web</category><category>Critical</category><category>magento</category><category>adobe-commerce</category><category>sessionreaper</category><category>file-upload</category><category>lfi</category><category>customer-address</category><category>form-key</category><category>cwe-434</category><category>python</category></item><item><title>WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</guid><description>High severity — web · CVE-2026-0740. Status: PoC. Affects: WordPress "Ninja Forms" plugin — file upload field/module. Tags: wordpress, ninja-forms, file-upload, webshell, admin-ajax, plugin-vulnerability, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>ninja-forms</category><category>file-upload</category><category>webshell</category><category>admin-ajax</category><category>plugin-vulnerability</category><category>cwe-434</category></item><item><title>WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3844-wordpress-breeze-cache-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3844-wordpress-breeze-cache-file-upload/</guid><description>Critical severity — web · CVE-2026-3844. Status: PoC. Affects: Breeze Cache plugin for WordPress. Tags: wordpress, wordpress-plugin, unauthenticated, file-upload, rce, gravatar-cache, breeze-cache.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>unauthenticated</category><category>file-upload</category><category>rce</category><category>gravatar-cache</category><category>breeze-cache</category></item><item><title>WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-5364. Status: PoC. Affects: WordPress plugin "Drag and Drop File Upload for Contact Form 7" (drag-and-drop-file-upload-for-contact-form-7). Tags: wordpress, contact-form-7, file-upload, webshell, rce, sanitize-file-name-bypass, admin-ajax, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>contact-form-7</category><category>file-upload</category><category>webshell</category><category>rce</category><category>sanitize-file-name-bypass</category><category>admin-ajax</category><category>cwe-434</category></item><item><title>WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation &amp; File Upload RCE (CVE-2026-27542 / CVE-2026-27540)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27542-woocommerce-wwlc-privesc-fileupload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27542-woocommerce-wwlc-privesc-fileupload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27542 (bundled with CVE-2026-27540). Status: Weaponized. Affects: WooCommerce Wholesale Lead Capture (WWLC) plugin for WordPress. Tags: wordpress, woocommerce, plugin, privilege-escalation, file-upload, rce, unauthenticated, mass-scanning.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>plugin</category><category>privilege-escalation</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>mass-scanning</category></item><item><title>VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</guid><description>High severity (CVSS 8.5) — web · CVE-2026-5615. Status: PoC. Affects: VvvebJs (drag-and-drop website builder). Tags: vvvebjs, stored-xss, svg-upload, file-upload, cms.</description><category>web</category><category>High</category><category>vvvebjs</category><category>stored-xss</category><category>svg-upload</category><category>file-upload</category><category>cms</category></item><item><title>User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4882-user-registration-advanced-fields-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4882-user-registration-advanced-fields-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-4882. Status: PoC. Affects: User Registration Advanced Fields plugin for WordPress. Tags: wordpress, wordpress-plugin, file-upload, webshell, unauthenticated, rce, nonce-leak.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>nonce-leak</category></item><item><title>TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</guid><description>Medium severity — web · CVE-2026-27621 (GHSA-xfvg-8v67-j7wp). Status: PoC. Affects: TypiCMS Core (typicms/core). Tags: typicms, stored-xss, svg-upload, cwe-79, cms, file-upload, laravel, session-hijack.</description><category>web</category><category>Medium</category><category>typicms</category><category>stored-xss</category><category>svg-upload</category><category>cwe-79</category><category>cms</category><category>file-upload</category><category>laravel</category><category>session-hijack</category></item><item><title>Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40487-postiz-svg-upload-xss/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-40487 / GHSA-44wg-r34q-hvfx. Status: PoC. Affects: Postiz (open-source social media management platform, gitroomhq/postiz-app). Tags: file-upload, mime-spoofing, stored-xss, account-takeover, postiz, nodejs, oauth-backdoor.</description><category>web</category><category>High</category><category>file-upload</category><category>mime-spoofing</category><category>stored-xss</category><category>account-takeover</category><category>postiz</category><category>nodejs</category><category>oauth-backdoor</category></item><item><title>Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4885-piotnet-elementor-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4885-piotnet-elementor-file-upload/</guid><description>Critical severity — web · CVE-2026-4885. Status: PoC. Affects: Piotnet Addons for Elementor Pro (WordPress plugin). Tags: wordpress, wordpress-plugin, elementor, piotnet, file-upload, webshell, unauthenticated, rce, mass-exploit.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>elementor</category><category>piotnet</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>mass-exploit</category></item><item><title>Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</guid><description>High severity (CVSS 8.7) — web · CVE-2026-3304. Status: PoC. Affects: Multer (Node.js multipart/form-data middleware for Express). Tags: multer, nodejs, express, dos, file-upload, orphaned-file, disk-exhaustion, multipart.</description><category>web</category><category>High</category><category>multer</category><category>nodejs</category><category>express</category><category>dos</category><category>file-upload</category><category>orphaned-file</category><category>disk-exhaustion</category><category>multipart</category></item><item><title>midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1306. Status: Weaponized. Affects: midi-Synth WordPress plugin. Tags: wordpress, wp-plugin, file-upload, cwe-434, webshell, ajax, mass-scanning.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>file-upload</category><category>cwe-434</category><category>webshell</category><category>ajax</category><category>mass-scanning</category></item><item><title>Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56290. Status: PoC. Affects: Page Builder CK (com_pagebuilderck) — Joomla extension. Tags: joomla, page-builder-ck, com_pagebuilderck, file-upload, unauth-rce, csrf, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>page-builder-ck</category><category>com_pagebuilderck</category><category>file-upload</category><category>unauth-rce</category><category>csrf</category><category>cms</category></item><item><title>Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</guid><description>High severity — web · CVE-2026-0911. Status: PoC. Affects: Hustle (wordpress-popup) plugin by WPMU DEV. Tags: wordpress, hustle, plugin, file-upload, rce, wp_handle_upload, orphan-file, authenticated, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>hustle</category><category>plugin</category><category>file-upload</category><category>rce</category><category>wp_handle_upload</category><category>orphan-file</category><category>authenticated</category><category>cwe-434</category></item><item><title>Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</guid><description>Info severity — web · CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)). Status: PoC. Affects: Fireshare (self-hosted video sharing app), &lt;= 1.16.3. Tags: fireshare, unauthenticated, arbitrary-file-write, argument-injection, ffmpeg, file-upload, cwe-73, docker.</description><category>web</category><category>Info</category><category>fireshare</category><category>unauthenticated</category><category>arbitrary-file-write</category><category>argument-injection</category><category>ffmpeg</category><category>file-upload</category><category>cwe-73</category><category>docker</category></item><item><title>EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</guid><description>Medium severity — web · CVE-2026-33534. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, ssrf, cwe-918, ipv4-obfuscation, authenticated, crm, file-upload, python.</description><category>web</category><category>Medium</category><category>espocrm</category><category>ssrf</category><category>cwe-918</category><category>ipv4-obfuscation</category><category>authenticated</category><category>crm</category><category>file-upload</category><category>python</category></item><item><title>Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</guid><description>Medium severity — web · CVE-2026-33033. Status: PoC. Affects: Django (django.http.multipartparser.MultiPartParser). Tags: django, dos, multipart, base64, cpu-amplification, python, file-upload.</description><category>web</category><category>Medium</category><category>django</category><category>dos</category><category>multipart</category><category>base64</category><category>cpu-amplification</category><category>python</category><category>file-upload</category></item><item><title>Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-29041. Status: Weaponized. Affects: Chamilo LMS. Tags: chamilo, lms, file-upload, rce, webshell, cwe-434, mime-bypass, authenticated.</description><category>web</category><category>High</category><category>chamilo</category><category>lms</category><category>file-upload</category><category>rce</category><category>webshell</category><category>cwe-434</category><category>mime-bypass</category><category>authenticated</category></item><item><title>BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6960-bookingpress-unauth-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6960-bookingpress-unauth-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-6960. Status: Weaponized. Affects: BookingPress Pro (WordPress appointment-booking plugin). Tags: wordpress, bookingpress, unauthenticated, file-upload, rce, data-uri, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>bookingpress</category><category>unauthenticated</category><category>file-upload</category><category>rce</category><category>data-uri</category><category>cwe-434</category></item><item><title>BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</guid><description>High severity — web · CVE-2026-39387. Status: Weaponized. Affects: BoidCMS. Tags: boidcms, php, authenticated, file-upload, path-traversal, template-injection, rce.</description><category>web</category><category>High</category><category>boidcms</category><category>php</category><category>authenticated</category><category>file-upload</category><category>path-traversal</category><category>template-injection</category><category>rce</category></item><item><title>Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</guid><description>High severity — web · CVE-2026-25099. Status: Weaponized. Affects: Bludit CMS (/api/files/&lt;page-key> endpoint). Tags: bludit, cms, file-upload, webshell, rce, php, api-token, cwe-434, authenticated.</description><category>web</category><category>High</category><category>bludit</category><category>cms</category><category>file-upload</category><category>webshell</category><category>rce</category><category>php</category><category>api-token</category><category>cwe-434</category><category>authenticated</category></item><item><title>AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21440-adonisjs-bodyparser-path-traversal/</guid><description>Critical severity (CVSS 9.2) — web · CVE-2026-21440 (GHSA-gvq6-hvvp-h34h). Status: Weaponized. Affects: @adonisjs/bodyparser (AdonisJS multipart file-upload handling). Tags: adonisjs, nodejs, path-traversal, arbitrary-file-write, cwe-22, file-upload, rce, bodyparser.</description><category>web</category><category>Critical</category><category>adonisjs</category><category>nodejs</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>file-upload</category><category>rce</category><category>bodyparser</category></item><item><title>Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48907. Status: Weaponized. Affects: Joomla Content Editor (JCE) extension by Widget Factory. Tags: RCE, unauthenticated, Joomla, JCE, CMS, access-control, webshell, php-webshell, file-upload, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Joomla</category><category>JCE</category><category>CMS</category><category>access-control</category><category>webshell</category><category>php-webshell</category><category>file-upload</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item><item><title>Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</guid><description>High severity (CVSS 7.8) — network · CVE-2026-20245. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), SD-WAN Validator (vBond). Tags: privilege-escalation, Cisco, SD-WAN, vManage, file-upload, command-injection, root, CISA-KEV, no-patch, Mandiant, nation-state.</description><category>network</category><category>High</category><category>privilege-escalation</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>file-upload</category><category>command-injection</category><category>root</category><category>CISA-KEV</category><category>no-patch</category><category>Mandiant</category><category>nation-state</category></item></channel></rss>