Total
3534 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-28700 | 1 Givewp | 1 Givewp | 2025-02-20 | 9.1 Critical |
| Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress. | ||||
| CVE-2022-25602 | 1 Expresstech | 1 Responsive Menu | 2025-02-20 | 8.3 High |
| Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7). | ||||
| CVE-2022-27862 | 1 Vikwp | 1 Vikbooking Hotel Booking Engine \& Property Management System Plugin | 2025-02-20 | 9.8 Critical |
| Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | ||||
| CVE-2022-29451 | 1 Rarathemes | 1 Rara One Click Demo Import | 2025-02-20 | 8.8 High |
| Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory. | ||||
| CVE-2022-40217 | 1 Xplodedthemes | 1 Wpide | 2025-02-20 | 6.5 Medium |
| Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. | ||||
| CVE-2022-40200 | 1 Gvectors | 1 Wpforo Forum | 2025-02-20 | 9.9 Critical |
| Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. | ||||
| CVE-2022-36386 | 1 Soflyy | 1 Wp All Import | 2025-02-20 | 9.1 Critical |
| Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress. | ||||
| CVE-2024-4681 | 1 Campcodes | 1 Legal Case Management System | 2025-02-20 | 4.7 Medium |
| A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability. | ||||
| CVE-2022-36285 | 1 Uploading Svg\, Webp And Ico Files Project | 1 Uploading Svg\, Webp And Ico Files | 2025-02-20 | 7.2 High |
| Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. | ||||
| CVE-2022-42698 | 1 Api2cart | 1 Api2cart Bridge Connector | 2025-02-20 | 9.8 Critical |
| Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress. | ||||
| CVE-2022-38140 | 1 Squirrly | 1 Seo Plugin By Squirrly Seo | 2025-02-20 | 7.6 High |
| Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. | ||||
| CVE-2022-45359 | 1 Yithemes | 1 Yith Woocommerce Gift Cards | 2025-02-20 | 9.8 Critical |
| Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. | ||||
| CVE-2023-40219 | 2 Coline, Welcart | 2 Welcart E-commerce, Welcart E-commerce | 2025-02-20 | 7.2 High |
| Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory. | ||||
| CVE-2024-10960 | 1 Brizy | 1 Brizy | 2025-02-20 | 9.9 Critical |
| The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | ||||
| CVE-2024-13544 | 1 Amini7 | 1 Zarinpal Paid Download | 2025-02-20 | 4.8 Medium |
| The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) | ||||
| CVE-2021-44967 | 1 Limesurvey | 1 Limesurvey | 2025-02-20 | 8.8 High |
| A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding. | ||||
| CVE-2024-57407 | 2025-02-19 | 7.3 High | ||
| An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file. | ||||
| CVE-2023-25828 | 1 Pluck-cms | 1 Pluck | 2025-02-19 | 7.2 High |
| Pluck CMS is vulnerable to an authenticated remote code execution (RCE) vulnerability through its “albums” module. Albums are used to create collections of images that can be inserted into web pages across the site. Albums allow the upload of various filetypes, which undergo a normalization process before being available on the site. Due to lack of file extension validation, it is possible to upload a crafted JPEG payload containing an embedded PHP web-shell. An attacker may navigate to it directly to achieve RCE on the underlying web server. Administrator credentials for the Pluck CMS web interface are required to access the albums module feature, and are thus required to exploit this vulnerability. CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C (8.2 High) | ||||
| CVE-2023-25909 | 1 Hgiga | 1 Oaklouds Portal | 2025-02-19 | 9.8 Critical |
| HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service. | ||||
| CVE-2023-27246 | 1 Mk-auth | 1 Mk-auth | 2025-02-18 | 8.8 High |
| An arbitrary file upload vulnerability in the Virtual Disk of MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted .htaccess file. | ||||