CVE-2024-49653
Unrestricted Upload of File with Dangerous Type vulnerability in James Eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through 1.2.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.19%
- CWE
- CWE-434, CWE-434
- Published
- 2024-10-23
- Last modified
- 2026-05-12
Affected products
- James Eggers Portfolleo
- james-eggers Portfolleo
Weakness type
Related vulnerabilities
- CVE-2026-84063 — BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous...
- CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 - Unauthenticated Arbitrary File Upload via 'type' Parameter
- CVE-2026-87928 — MaxSite CMS 0.94 through 109.6 HTML Upload XSS via admin_page
- CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173),...
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload