Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Iptanus File Upload — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Iptanus File Upload, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerabilities associated with the Iptanus File Upload software, focusing on the file upload weakness category under the CWE tag. The collection aggregates security reports covering a broad time range from early releases to the present, ensuring comprehensive historical coverage of known issues. By organizing these findings, the platform enables researchers and administrators to effectively track vendor advisories and monitor the patch lifecycle for this specific product. Users can utilize this resource to understand the evolution of the file upload weakness class within the context of Iptanus File Upload, observing how attack vectors and severity ratings have changed over time. The data supports detailed analysis of a product's vulnerability history, helping stakeholders assess risk exposure and remediation urgency. This structured approach facilitates the identification of persistent flaws and recurring patterns in file handling logic, which are critical for secure software development. It serves as a centralized reference for security professionals seeking to evaluate the impact of these weaknesses on organizational infrastructure. The content is curated to provide clear insights into mitigation strategies and affected versions, aiding in the prioritization of security patches. Ultimately, this page aims to enhance transparency and support informed decision-making regarding the adoption and maintenance of Iptanus File Upload in enterprise environments.

Vendor: nickboss

CVE ID Title CVSS Severity Published
CVE-2026-17044 WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid - - 2026-08-09
CVE-2025-15546 Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition - - 2026-06-14
CVE-2024-13494 WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details CWE-352 4.3 Medium 2025-02-25
CVE-2024-9939 WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php CWE-22 7.5 High 2025-01-08
CVE-2024-11635 WordPress File Upload <= 4.24.12 - Unuathenticated Remote Code Execution CWE-94 9.8 Critical 2025-01-08
CVE-2024-11613 WordPress File Upload <= 4.24.15 - Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion CWE-94 9.8 Critical 2025-01-08
CVE-2024-12719 WordPress File Upload <= 4.24.15 - Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal CWE-862 4.3 Medium 2025-01-07
CVE-2024-9047 WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php CWE-22 9.8 Critical 2024-10-12
CVE-2024-7301 WordPress File Upload <= 4.24.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload CWE-79 7.2 High 2024-08-16
CVE-2024-5852 WordPress File Upload <= 4.24.7 - Authenticated (Contributor+) Directory Traversal CWE-22 4.3 Medium 2024-07-16
CVE-2024-2847 WordPress File Upload <= 4.24.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-04-09
CVE-2023-2688 WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal CWE-22 4.9 Medium 2023-06-09
CVE-2023-2767 WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium 2023-06-09

All 13 known CVE vulnerabilities affecting Iptanus File Upload with full Chinese analysis, references, and POCs where available.