An unauthenticated arbitrary file upload vulnerability in the SP Page Builder extension for Joomla versions prior to 6.6.2. The vulnerability allows remote attackers to upload and execute arbitrary PHP files without authentication. CVSS score: 10.0.
DetailsResearch
Security Research
Security research, vulnerability analysis, technical experiments, and responsible disclosure work documented from hands-on learning.
A critical unauthenticated arbitrary file upload vulnerability in the Forminator Forms plugin for WordPress versions up to and including 1.56.1. Insufficient file type validation in the handle_file_upload function allows remote attackers to upload PHP files. CVSS score: 9.8.
Two chained vulnerabilities in PaperCut NG/MF print management software: an authentication bypass (CVE-2026-81578, CVSS 8.8) and an unsafe dynamic class loading issue (CVE-2026-82078, CVSS 9.4). Both were added to CISA's Known Exploited Vulnerabilities catalog.
Details