37 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-81402 | The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type v | CRITICAL | 9.8 | 38%ile | NVD | 2026-09-12 |
| CVE-2026-84171 | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before | CRITICAL | 9.8 | 31%ile | NVD | 2026-09-12 |
| CVE-2026-87796 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, | CRITICAL | 9.8 | 48%ile | NVD | 2026-09-17 |
| CVE-2026-45140 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a | CRITICAL | 9.8 | 61%ile | NVD | 2026-09-17 |
| CVE-2026-50006 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL fro | CRITICAL | 9.1 | 54%ile | NVD | 2026-09-14 |
| CVE-2026-83163 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-78088 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unaut | HIGH | 8.8 | 47%ile | NVD | 2026-09-16 |
| CVE-2026-76552 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it re | HIGH | 8.8 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-86801 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress an | HIGH | 8.8 | 27%ile | NVD | 2026-09-17 |
| CVE-2026-93031 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-82780 | Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uplo | HIGH | 8.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-92970 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authentic | HIGH | 8.7 | 43%ile | NVD | 2026-09-17 |
| CVE-2026-77929 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-82793 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Convert | HIGH | 8.6 | 29%ile | NVD | 2026-09-14 |
| CVE-2026-81236 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-81239 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-81240 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-92980 | HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrato | HIGH | 8.6 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-87935 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1 | HIGH | 8.1 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie | HIGH | 7.6 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-54567 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask | HIGH | 7.5 | 47%ile | NVD | 2026-09-14 |
| CVE-2026-81090 | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the | HIGH | 7.2 | 19%ile | NVD | 2026-09-12 |
| CVE-2026-90603 | A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unkn | MEDIUM | 6.9 | 40%ile | NVD | 2026-09-13 |
| CVE-2023-34854 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | MEDIUM | 6.6 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-54177 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 6.6 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-88618 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This | MEDIUM | 6.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-56590 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c | MEDIUM | 6.4 | 7%ile | NVD | 2026-09-18 |
| CVE-2026-84048 | Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < | MEDIUM | 6.3 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-86861 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested pat | MEDIUM | 6.0 | 38%ile | NVD | 2026-09-17 |
| CVE-2026-57581 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applic | MEDIUM | 5.3 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-93506 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/ | MEDIUM | 5.3 | — | NVD | 2026-09-18 |
| CVE-2026-90500 | A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of | LOW | 2.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-90519 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the f | LOW | 2.1 | 12%ile | NVD | 2026-09-13 |
| CVE-2026-90857 | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown funct | LOW | 2.1 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-91005 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded | LOW | 2.1 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-91849 | A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /in | LOW | 2.1 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92247 | A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename o | LOW | 2.0 | 22%ile | NVD | 2026-09-16 |