CVE-2018-9207

CRITICAL

jQuery Upload File <= 4.0.2 - Arbitrary File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-9207. PoCs published by cved-sources.

AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2018-9207, which involves an arbitrary file upload vulnerability in jQuery Upload File plugin version 4.0.5. The vulnerability allows attackers to upload malicious files to the server due to insufficient file type validation.

Description

Arbitrary file upload in jQuery Upload File <= 4.0.2

Exploits (1)

nomisec WORKING POC
by cved-sources · poc
https://github.com/cved-sources/cve-2018-9207

This repository contains a proof-of-concept for CVE-2018-9207, which involves an arbitrary file upload vulnerability in jQuery Upload File plugin version 4.0.5. The vulnerability allows attackers to upload malicious files to the server due to insufficient file type validation.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: jQuery Upload File plugin 4.0.5
No auth needed
Prerequisites: Access to the upload functionality of the jQuery Upload File plugin
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://www.vapidlabs.com/advisory.php?v=206

Scores

CVSS v3 9.8
EPSS 0.2757
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
hayageek/jquery_upload_file < 4.0.2
npm/jquery-file-upload 0 - 4.0.5npm
Published Nov 19, 2018
Tracked Since Feb 18, 2026