VYPR

Iptanus File Upload

by WordPress

CVEs (3)

  • CVE-2026-17044HigAug 9, 2026
    risk 0.56cvss 8.6epss 0.00

    The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.

  • CVE-2018-9172MedApr 1, 2018
    risk 0.38cvss 5.4epss 0.03

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

  • CVE-2025-15546Jun 14, 2026
    risk 0.00cvss epss 0.00

    The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…