upload
-
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. This vulnerability is traded as CVE-2025-2687. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
-
A vulnerability has been found in GE Fanuc Proficy Real-Time Information Portal up to 2.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation leads to memory corruption. This vulnerability is known as CVE-2008-0175. The attack can be launched remotely. Furthermore, there is an exploit…
-
A vulnerability classified as critical was found in Bludit 3.0.0. Affected by this vulnerability is an unknown functionality of the component Pages Editor. The manipulation leads to unrestricted upload. This vulnerability is known as CVE-2018-1000811. The attack can be launched remotely. Furthermore, there is an exploit available.
-
A vulnerability was found in BigTree CMS 4.2.23. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/ajax/file-browser/upload/ of the component Image Upload. The manipulation leads to cross site scripting (Stored). This vulnerability is handled as CVE-2018-18308. The attack may be launched remotely. Furthermore, there is an…
-
A vulnerability classified as problematic has been found in Terry Lin WP Githuber MD Plugin up to 1.16.2 on WordPress. Affected is an unknown function. The manipulation leads to unrestricted upload. This vulnerability is traded as CVE-2023-47846. It is possible to launch the attack remotely. There is no exploit available.
-
CVE-2023-47873 | WEN Solutions WP Child Theme Generator up to 1.0.9 on WordPress unrestricted upload
·
A vulnerability was found in WEN Solutions WP Child Theme Generator up to 1.0.9 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. This vulnerability was named CVE-2023-47873. The attack can be initiated remotely. There is no exploit available.
-
A vulnerability has been found in JupiterX Core Premium Plugin up to 3.3.5 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. This vulnerability was named CVE-2023-38388. The attack can be initiated remotely. There is no exploit available.
-
CVE-2024-6896 | AMP for WP Plugin up to 1.0.96.1 on WordPress SVG File Upload cross site scripting
·
A vulnerability has been found in AMP for WP Plugin up to 1.0.96.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the component SVG File Upload. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-6896. The attack can be initiated remotely. There is no exploit available.
-
A vulnerability, which was classified as critical, was found in Theme Egg ToolKit Plugin up to 1.2.9 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2025-28915. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
-
A vulnerability was found in aThemes Starter Sites Plugin up to 1.0.53 on WordPress. It has been classified as problematic. This affects an unknown part of the component SVG File Upload Handler. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-6897. It is possible to initiate the attack remotely. There…
-
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2024-7342. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. The…
-
A vulnerability was found in File Upload Plugin up to 4.24.7 on WordPress and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-6494. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected…
-
A vulnerability classified as problematic was found in nickboss File Upload Plugin up to 4.24.8 on WordPress. This vulnerability affects unknown code of the component SVG File Handler. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-7301. The attack can be initiated remotely. There is no exploit available.
-
CVE-2024-7304 | Ninja Tables Plugin up to 5.0.12 on WordPress SVG File Upload cross site scripting
·
A vulnerability was found in Ninja Tables Plugin up to 5.0.12 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SVG File Upload Handler. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2024-7304. The attack may be launched remotely. There is…
-
CVE-2024-8370 | Grocy up to 4.2.0 SVG File Upload recipepictures force_serve_as cross site scripting
·
A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG File Upload Handler. The manipulation of the argument force_serve_as with the input picture’ leads to cross site scripting. This vulnerability was named CVE-2024-8370. The attack can be initiated remotely. Furthermore,…
-
A vulnerability, which was classified as problematic, was found in ownCloud up to 6.0.0. This affects an unknown part of the component File Upload. The manipulation of the argument filename leads to cross site scripting. This vulnerability is uniquely identified as CVE-2014-1665. It is possible to initiate the attack remotely. Furthermore, there is an exploit…
-
A vulnerability classified as critical has been found in IBM Engineering Lifecycle Optimization Publishing 7.0.2/7.0.3. This affects an unknown part of the component Request Handler. The manipulation leads to unrestricted upload. This vulnerability is uniquely identified as CVE-2023-45188. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to…
-
A vulnerability, which was classified as problematic, has been found in besnikac Graphicsly Plugin up to 1.0.2 on WordPress. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-9069. The attack may be initiated remotely. There is no…