SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-57784

CRITICAL · CVSS 9.6 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Ninja Forms File Uploads Extension versions up to 3.3.26 are vulnerable to an unauthenticated Cross Site Request Forgery (CSRF) attack, allowing attackers to exploit the file upload functionality without user authentication. This critical vulnerability could lead to unauthorized file uploads, potentially compromising the integrity and security of the affected applications. Organizations using this extension should prioritize immediate patching or mitigation efforts to safeguard against potential exploitation.

CVE
CVE-2026-57784
Severity
CRITICAL
CVSS
9.6
EPSS
0.13%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.