Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and sty…
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG tha…
CVSS 8.7
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensi…
CVSS 7.2
Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
CVSS 10
Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.
CVSS 9.9
Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.
CVSS 9.9
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions.
CVSS 9.9
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
CVSS 10
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation …
CVSS 8.8
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL t…
CVSS 7.5
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage ad…
CVSS 7.3
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any…
CVSS 7.3