Security Risk Category

File Upload Security Risks — Page 2

Published vulnerability pages connected to File Upload. Each page keeps one canonical URL and focused remediation guidance.

47 published File Upload risks

File Upload risks

Showing 37–47 of 47 published risks.

criticalEPSS 0.005

Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

CVE-2026-14894wordpressremote-code-executionfile-uploadfile-write

Updated Jul 13, 2026

mediumEPSS 0.003

CVE-2026-59217 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to a target knowledge base without applying the write-access check used by /api/v1/knowledge//file/add, allowing read-only knowledge-base users to add arbitrary files. This issue is fixed in version 0.10.0.

CVE-2026-59217api-securityweb-applicationauthorization-bypassfile-upload

Updated Jul 12, 2026

mediumEPSS 0.003

CVE-2026-43752 Claris FileMaker Server vulnerability

An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

CVE-2026-43752web-applicationremote-code-executionfile-upload

Updated Jul 12, 2026

criticalCISA KEVEPSS 0.015

CVE-2026-48939 iCagenda for Joomla vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVE-2026-48939joomlaphpweb-applicationremote-code-execution

Updated Jul 12, 2026

mediumEPSS 0.006

CVE-2026-55078 Coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer. Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service). The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 adds a metadata preflight check that sums projected entry sizes and a streaming writer that enforces the aggregate limit during decompression. As a workaround, restrict file-upload permissions to trusted users or place a reverse proxy with request-body size limits in front of `Coderd`.

CVE-2026-55078api-securitydevopsdenial-of-servicefile-upload

Updated Jul 12, 2026

criticalEPSS 0.010

Blocksy Companion Pro Arbitrary File Upload RCE Vulnerability

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.woff2.php to pass MIME validation and be handled as permitted font files. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This vulnerability is only exploitable when the premium version of the plugin (blocksy-companion-pro) is installed with both the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active; the free blocksy-companion plugin does not contain the vulnerable code paths.

CVE-2026-15158wordpresswoocommercephpremote-code-execution

Updated Jul 10, 2026

critical

Balbooa Forms Joomla Extension Arbitrary File Upload RCE Vulnerability

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVE-2026-56291joomlaphpremote-code-executionfile-upload

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.014

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVE-2026-48908phpfile-uploadfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.007

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CVE-2026-56290joomlaremote-code-executionauthorization-bypassfile-upload

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.919

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

CVE-2024-7399path-traversalfile-uploadfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.039

Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

CVE-2025-2749path-traversalfile-upload

Updated Jul 9, 2026