CVE Browser

More filters (active)
CVE-2025-14457 HIGH

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.2 - Missing Authorization to Unauthenticated File Deletion

CVSS 7.4 EPSS 0.22% Jan 15, 2026
CVE-2025-5746 CRITICAL

Drag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload

CVSS 9.8 EPSS 0.74% Jul 2, 2025
CVE-2025-3515 CRITICAL

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks

CVSS 9.8 EPSS 5.82% Jun 17, 2025
CVE-2025-2485 HIGH

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion

CVSS 8.8 EPSS 0.59% Mar 28, 2025
CVE-2025-2328 HIGH

Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion

CVSS 8.8 EPSS 1.09% Mar 28, 2025
CVE-2024-12267 CRITICAL

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion

CVSS 9.1 EPSS 0.33% Jan 31, 2025
CVE-2024-3717 HIGH

Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure

CVSS 7.5 EPSS 0.71% May 2, 2024
CVE-2022-45377 CRITICAL

WordPress Drag and Drop Multiple File Upload for WooCommerce Plugin <= 1.0.8 is vulnerable to Multiple Vulnerabilities

CVSS 9.8 EPSS 0.60% Dec 21, 2023
CVE-2023-5822 CRITICAL

Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload

CVSS 9.8 EPSS 1.79% Nov 22, 2023
CVE-2023-4821 MEDIUM

Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting

CVSS 5.4 EPSS 0.45% Oct 16, 2023
CVE-2022-45364 HIGH

WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF)

CVSS 8.8 EPSS 0.25% May 24, 2023
CVE-2023-1282 MEDIUM

Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scripting

CVSS 6.1 EPSS 0.54% Apr 17, 2023
CVE-2023-1112 CRITICAL

Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal

CVSS 9.8 EPSS 3.00% Mar 1, 2023
CVE-2022-3282 MEDIUM

Drag and Drop Multiple File Upload < 1.3.6.5 - File Upload Size Limit Bypass

CVSS 4.3 EPSS 0.59% Oct 17, 2022
CVE-2022-0595 MEDIUM

Drag and Drop Multiple File Upload - Contact Form 7 < 1.3.6.3 - Unauthenticated Stored XSS

CVSS 5.4 EPSS 13.58% Mar 28, 2022
CVE-2020-12800 CRITICAL

The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting…

CVSS 9.8 EPSS 78.61% Jun 8, 2020

Showing 1 to 16 CVEs · page 1