References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/%E7%94%A8%E5%8F%8B-%E7%95%85%E6%8D%B7%E9%80%9AT+-Upload.aspx-%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/pursue-security/p/17684758.html https://stack.chaitin.com/vuldb/detail/157cc620-700c-47f7-9aa8-c3590a6cca04 https://zhuanlan.zhihu.com/p/622179945 https://whoopscs.com/posts/cnvd-2022-60632/ https://blog.nsfocus.net/t/ https://github.com/izj007/wechat/blob/main/articles/%5BZ2O%E5%AE%89%E5%85%A8%E6%94%BB%E9%98%B2%5D-2022-9-23-CNVD-2022-60632%20%E7%95%85%E6%8D%B7%E9%80%9A%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0.md https://juejin.cn/post/7317878585943130164 https://www.cnblogs.com/bmjoker/p/16794685.html https://zone.ci/aliyun/ali_highrisk/305999.html https://www.secrss.com/articles/46391 https://cn-sec.com/archives/1844958.html
Related VulnerabilitiesPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File Upload畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞PoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload二一零零科技|公文管理系統 - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEPoCCVE-2026-14483: Realtyna Organic IDX/WPL <= 5.2.0 - Unauthenticated Arbitrary File Upload