Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
41 articles

#File Upload

All CosmicBytez Labs articles tagged #File Upload, across news, security advisories, how-to guides, and projects.

  • SecurityAug 30, 2026

    Sigma Forms Pro WordPress Plugin: Unauthenticated RCE via File Upload (CVE-2026-14494)

    CVE-2026-14494 (CVSS 9.8) lets unauthenticated attackers upload PHP webshells through Sigma Forms Pro's default form templates. No patch yet.

  • NewsAug 20, 2026

    Critical Elementor Pro Bug Exposes WordPress Sites to RCE Attacks

    CVE-2026-32475 (CVSS 9.0): Unauthenticated attackers can upload PHP webshells via a loop desync flaw in Elementor Pro's file upload field.

  • NewsAug 17, 2026

    Forminator WordPress Plugin Flaw Enables Unauthenticated RCE via PHP Upload

    CVE-2026-15748 (CVSS 9.8) in Forminator Forms allows unauthenticated PHP webshell uploads for full RCE on 600,000+ WordPress sites. Patch to 1.56.2 now.

  • SecurityAug 16, 2026

    CVE-2026-18438: Templately WordPress Plugin RCE via File Upload

    CVSS 8.8 flaw in Templately for WordPress lets authenticated subscribers execute arbitrary code via a filename validation bypass in file upload.

  • SecurityAug 15, 2026

    CVE-2026-72819: Grav CMS RCE via ZIP Upload Bypass in Flex Objects Plugin

    Grav CMS before 2.0.13 allows authenticated users to achieve RCE by bypassing filename validation with PHP-laden ZIP files.

  • SecurityAug 11, 2026

    CVE-2026-13716: Path Traversal RCE in Crafty Controller

    A critical path traversal vulnerability in Crafty Controller allows authenticated remote attackers to upload files to arbitrary paths and achieve remote code execution via the server import and admin file upload features.

  • SecurityAug 8, 2026

    CVE-2022-4995: Weaver E-cology 9.0 Unauthenticated File Upload Enables Webshell RCE

    A critical unauthenticated file upload vulnerability in Weaver E-cology 9.0 allows attackers to upload JSP webshells through a vulnerable endpoint, achieving full remote code execution. The flaw has been actively exploited since at least October 2023.

  • SecurityJul 29, 2026

    CVE-2026-63227: Koollab LMS SCORM File Upload Allows Webshell Deployment and RCE

    A CVSS 9.9 critical vulnerability in Koollab LMS allows authenticated module designers to upload a SCORM package containing a PHP webshell to a publicly accessible directory, achieving remote code execution on the server.

  • SecurityJul 27, 2026

    CVE-2026-13714: Realtyna IDX Plugin Unauthenticated File Upload via Hardcoded Credentials

    A critical CVSS 9.8 unauthenticated arbitrary file upload vulnerability in the Realtyna Organic IDX + WPL Real Estate WordPress plugin (before v5.3.0) exploits hardcoded credentials shipped identically across all installations.

  • SecurityJul 25, 2026

    CVE-2026-10818: WPForms Pro Arbitrary File Upload — Unauthenticated RCE

    A high-severity vulnerability in WPForms Pro allows unauthenticated attackers to upload malicious files and achieve remote code execution. File type...

  • SecurityJul 24, 2026

    GoDAM WordPress Plugin Arbitrary File Upload — CVE-2026-14282

    A critical unauthenticated arbitrary file upload vulnerability in the GoDAM WordPress media library plugin allows attackers to upload malicious files and...

  • SecurityJul 22, 2026

    CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload

    The Joomla extension Membership Pro prior to version 4.6.2 allowed unauthenticated users to upload media assets by default, exposing sites to potential...

  • SecurityJul 18, 2026

    CVE-2026-48062: CodeIgniter File Upload Validation Bypass (CVSS 9.8)

    CodeIgniter versions prior to 4.7.3 contain a critical file upload validation flaw where the ext_in rule checks MIME-derived extensions instead of...

  • SecurityJul 12, 2026

    CVE-2026-15488: Unrestricted File Upload in shiroiAdmin Enables Remote Code Execution

    A high-severity unrestricted file upload vulnerability in shiroiAdmin versions 1.1 and 1.3 allows unauthenticated remote attackers to upload PHP webshells...

  • SecurityJul 11, 2026

    CVE-2026-48939: iCagenda Unrestricted File Upload Allows PHP Code Execution

    A critical unrestricted file upload vulnerability in the iCagenda Joomla event calendar plugin allows unauthenticated attackers to upload arbitrary PHP...

  • SecurityJul 10, 2026

    CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload

    A critical unauthenticated arbitrary file upload vulnerability in the Super Forms plugin for WordPress (CVSS 9.8) allows attackers to upload and execute...

  • SecurityJul 10, 2026

    CVE-2026-15158: WordPress Blocksy Companion Arbitrary File Upload (CVSS 9.8)

    A critical arbitrary file upload vulnerability in the Blocksy Companion WordPress plugin (versions up to 2.1.46) allows unauthenticated attackers to...

  • SecurityJul 10, 2026

    CVE-2026-15282: WordPress Instant Appointment Plugin Critical File Upload

    A critical unauthenticated arbitrary file upload flaw (CVSS 9.8) in the Instant Appointment WordPress plugin allows attackers to upload and execute...

  • SecurityJul 10, 2026

    CVE-2026-56291: Balbooa Forms Unrestricted File Upload Enables Full RCE

    A critical unauthenticated file upload vulnerability in Balbooa Forms for Joomla allows attackers to upload executable files and achieve full remote code...

  • SecurityJul 7, 2026

    CVE-2026-56290: Joomlack Page Builder Unauthenticated File Upload RCE — CISA KEV

    A CVSS 10.0 unauthenticated arbitrary file upload vulnerability in the Joomlack Page Builder CK Joomla extension allows any remote attacker to upload a...

  • SecurityJul 5, 2026

    CVE-2026-14635: Unrestricted File Upload RCE in CodeIgniter Ecommerce Bootstrap

    A high-severity unrestricted file upload vulnerability in the kirilkirkov Ecommerce-CodeIgniter-Bootstrap allows authenticated vendor users to upload...

  • SecurityJul 1, 2026

    CVE-2026-48276: Adobe ColdFusion Critical File Upload RCE (CVSS 10.0)

    Adobe ColdFusion versions 2023.20 and 2025.9 and earlier contain a critical unrestricted file upload vulnerability that allows unauthenticated remote...

  • SecurityJun 19, 2026

    CVE-2026-54414: FileRise Path Traversal Enables Arbitrary File Write and Admin Takeover

    A critical path traversal vulnerability in FileRise before 3.16.0 allows unauthenticated attackers to write arbitrary files and completely compromise...

  • SecurityJun 16, 2026

    CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

    WordPress CP Polls plugin version 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through...

  • SecurityJun 12, 2026

    CVE-2026-11839: Unrestricted File Upload Enables Web Shell Deployment in Rotaban

    A critical unrestricted file upload vulnerability in the Rotaban platform by Basarsoft Information Technologies allows authenticated attackers to upload...

  • SecurityJun 6, 2026

    CVE-2026-7537: MDJM Event Management WordPress Plugin Arbitrary File Upload

    A high-severity arbitrary file upload vulnerability in the MDJM Event Management plugin for WordPress allows authenticated attackers to upload malicious files…

  • SecurityMay 31, 2026

    CVE-2018-25412: Arbitrary File Upload RCE in Delta Sql 1.8.2

    A critical unauthenticated arbitrary file upload vulnerability in Delta Sql 1.8.2 allows attackers to upload malicious PHP files and achieve remote code...

  • SecurityMay 14, 2026

    CVE-2026-45053: CubeCart REST API Arbitrary PHP File Upload

    A critical arbitrary file upload vulnerability in CubeCart's REST API File Manager allows holders of a files:rw API key to upload PHP webshells to the web...

  • SecurityMay 11, 2026

    CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File

    MStore API 2.0.6 for WordPress allows unauthenticated attackers to upload arbitrary PHP files via the REST API config_file endpoint, achieving remote code...

  • SecurityMay 11, 2026

    CVE-2021-47936: OpenCATS 0.9.4 Unauthenticated RCE via PHP

    OpenCATS 0.9.4 allows unauthenticated attackers to upload malicious PHP files through the careers job application endpoint, achieving remote code...

  • SecurityMay 2, 2026

    CVE-2026-4882: Unauthenticated File Upload in WordPress

    A critical unauthenticated arbitrary file upload vulnerability in the User Registration Advanced Fields plugin for WordPress allows attackers to upload...

  • SecurityApr 24, 2026

    CVE-2026-41309: OSSN Resource Exhaustion via Crafted Pixel

    Open Source Social Network (OSSN) versions prior to 9.0 are vulnerable to resource exhaustion via specially crafted image uploads with extreme pixel...

  • NewsApr 23, 2026

    Hackers Actively Exploiting Breeze Cache File Upload Bug in WordPress Attacks

    Threat actors are mass-exploiting a critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin, uploading PHP webshells to...

  • SecurityApr 23, 2026

    CVE-2026-3844 — Breeze Cache WordPress Plugin

    A critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin allows attackers to upload arbitrary files to affected servers...

  • SecurityApr 21, 2026

    CVE-2025-2749: Kentico Xperience Path Traversal

    Kentico Xperience contains a path traversal vulnerability allowing an authenticated user's Staging Sync Server to upload arbitrary data to relative path...

  • SecurityApr 18, 2026

    CVE-2026-6518: WordPress CMP Plugin Arbitrary File Upload

    The CMP Coming Soon & Maintenance Plugin for WordPress contains a critical arbitrary file upload flaw that allows subscriber-level authenticated users to...

  • SecurityApr 11, 2026

    CVE-2026-6057: FalkorDB Browser Unauthenticated Path

    FalkorDB Browser 1.9.3 contains a critical unauthenticated path traversal vulnerability in its file upload API that allows remote attackers to write...

  • SecurityApr 9, 2026

    CVE-2026-1830: WordPress Quick Playground Plugin RCE via Unauthenticated File Upload

    A critical CVSS 9.8 vulnerability in the Quick Playground WordPress plugin (versions up to 1.3.1) allows unauthenticated attackers to upload arbitrary...

  • SecurityApr 5, 2026

    CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload

    Snews CMS 1.7 contains a critical unrestricted file upload vulnerability allowing unauthenticated attackers to upload PHP webshells to the snews_files...

  • SecurityMar 16, 2026

    CVE-2015-20115: RealtyScript 4.0.2 Stored XSS via File

    CVE-2015-20115 is a stored cross-site scripting vulnerability in RealtyScript 4.0.2 that allows authenticated attackers to upload malicious script files...

  • SecurityFeb 12, 2026

    Critical RCE in WPvivid Backup Plugin Threatens 900,000+

    A critical unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin allows remote code execution on over 900,000...