Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2023-06-22 CVE-2023-27083 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.15/4.7.16
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-22 CVE-2023-36097 Unrestricted Upload of File with Dangerous Type vulnerability in Funadmin 3.3.2/3.3.3
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
network
low complexity
funadmin CWE-434
critical
9.8
2023-06-20 CVE-2020-20067 Unrestricted Upload of File with Dangerous Type vulnerability in Ebcms 1.1.0
File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.
network
low complexity
ebcms CWE-434
8.8
2023-06-20 CVE-2020-20718 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluckcms 4.7.10
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
network
low complexity
pluck-cms CWE-434
critical
9.8
2023-06-20 CVE-2020-20735 Unrestricted Upload of File with Dangerous Type vulnerability in 8Cms Ljcms 4.3.R60321
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
network
low complexity
8cms CWE-434
critical
9.8
2023-06-20 CVE-2020-20919 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-20969 Unrestricted Upload of File with Dangerous Type vulnerability in Pluck-Cms Pluck 4.7.10
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
network
low complexity
pluck-cms CWE-434
7.2
2023-06-20 CVE-2020-21174 Unrestricted Upload of File with Dangerous Type vulnerability in Feehi Feehicms 2.0.7.1
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
network
low complexity
feehi CWE-434
critical
9.8
2023-06-20 CVE-2020-21325 Unrestricted Upload of File with Dangerous Type vulnerability in Wuzhicms 4.1.0
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.
network
low complexity
wuzhicms CWE-434
8.8
2023-06-20 CVE-2020-21474 Unrestricted Upload of File with Dangerous Type vulnerability in Nucleuscms 3.71
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
network
low complexity
nucleuscms CWE-434
critical
9.8