Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-28951

Опубликовано: 04 июл. 2025
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue affects Bulk Featured Image: from n/a through 1.2.1.

EPSS

Процентиль: 20%
0.00063
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.1
github
7 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue affects Bulk Featured Image: from n/a through 1.2.1.

EPSS

Процентиль: 20%
0.00063
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-434