Tag

#Unrestricted File Upload

articleCRITICAL 10.0

Critical Vulnerability in Embed HTML5 Game WordPress Plugin Allows Unauthenticated PHP Backdoor Uploads

A critical vulnerability, CVE-2026-4357, with a CVSS score of 10, was discovered in the Embed HTML5 Game WordPress plugin (version 1.3 and below). This vulnerability allows unauthenticated attackers to upload PHP backdoors on affected sites, potentially leading to remote code execution, data breaches, and site takeovers. Immediate patching or mitigation is essential to prevent exploitation. The vulnerability has not been actively exploited yet, but its severity and potential impact warrant urgent attention.

1 source
blogCRITICAL 9.9

Unrestricted SCORM File Upload Vulnerability in Koollab LMS: A Critical Threat

CVE-2026-63227 is a critical vulnerability in Koollab LMS that allows an authenticated module designer to upload a malicious SCORM package containing a PHP webshell, leading to arbitrary code execution on the server. This vulnerability has a CVSS score of 9.9 and is classified as CWE-434. Although not actively exploited, it poses a significant threat to affected systems.

1 source
articleHIGH 8.8

Authenticated File Upload Vulnerability in Vtiger CRM Leading to Remote Code Execution (CVE-2026-23697)

A critical vulnerability (CVE-2026-23697) has been discovered in Vtiger CRM versions prior to 8.4.0. This authenticated file upload vulnerability allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module. The vulnerability has a CVSS score of 8.8 and is considered high severity. Organizations using affected versions of Vtiger CRM should immediately upgrade to version 8.4.0 or apply recommended mitigations.

1 source