PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2018-9206

9.8
CVSS
Description

Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

Attack Vector
-
Privileges Req.
-
User Interaction
-
blueimp jquery-file-upload
Updated Sep 18, 2026View on NVD →
S4E scanner

Blueimp jQuery-File-Upload v9.22.0 - Unrestricted File Upload

Blueimp jQuery-File-Upload v9.22.0 contains an unauthenticated arbitrary file upload caused by insufficient validation in the upload component, letting remote attackers upload malicious files, exploit requires no authentication. References: https://www.exploit-db.com/exploits/45790 https://www.exploit-db.com/exploits/46182/ https://github.com/blueimp/jQuery-File-Upload/pull/3514 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/jquery_file_upload.rb Remediation: Update to the latest version of Blueimp jQuery-File-Upload.

Used 2.5k times · domain, subdomain, ipv4

CVE history: blueimp jquery-file-upload

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →