CVE-2026-65455
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVSS
9.1
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-434
Not enough EPSS history yet.
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-654619.1 CRI—
——0Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.4hCVE-2026-270649.1 CRI—
——0Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.4hCVE-2026-142829.8 CRI66.4%
——20The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hooked into WPForms' public wpforms_process_before_filter, which trusts the attacker-supplied multipart Content-Type header, preserves the original filename via wp_unique_filename(), and moves the raw upload with $wp_filesystem->move() into a web-served directory — bypassing wp_handle_upload()'s MIME/extension allowlist. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.6hCVE-2026-63048—13.4%
——4The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.20hCVE-2026-164516.3 MED25.6%
——8A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument File results in unrestricted upload. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.1dCVE-2026-164477.3 HIG50.4%
——15A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.1d