CVE-2026-32579
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
CVSS
10.0
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-434
Sin historial EPSS suficiente todavía.
Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-105868——
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, local upload configurations that accept XML files can store an XML file and stylesheet that execute JavaScript in the Payload origin when a logged-in user opens the file. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.48mCVE-2026-1058628.7 ALT—
———Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a collection that allows downloadable SVG uploads can store a malicious SVG that bypasses sanitization and executes attacker-controlled JavaScript when a user downloads and opens the SVG. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.48mCVE-2026-1040697.2 ALT—
———HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it under the themes directory to execute arbitrary OS commands as the web-server user.4hCVE-2026-3977010.0 CRÍ—
———Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.6hCVE-2026-397599.9 CRÍ—
———Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions.6hCVE-2026-397579.9 CRÍ—
———Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions.6h