
CVE-2025-1306
Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.