Iptanus File Upload
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-17044 | Hig | 0.56 | 8.6 | 0.00 | Aug 9, 2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | ||
| CVE-2018-9172 | Med | 0.38 | 5.4 | 0.03 | Apr 1, 2018 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | ||
| CVE-2025-15546 | 0.00 | — | 0.00 | Jun 14, 2026 | The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file… |
- risk 0.56cvss 8.6epss 0.00
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
- risk 0.38cvss 5.4epss 0.03
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
- CVE-2025-15546Jun 14, 2026risk 0.00cvss —epss 0.00
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the file existence check and the actual file…