We have discovered 40,962 live websites that are affected by CWE-73.
| 10,936 websites | |
| 5,331 websites | |
| 3,508 websites | |
| 2,104 websites | |
| 1,593 websites | |
| 1,233 websites | |
| 1,157 websites | |
| 939 websites | |
| 874 websites | |
| 848 websites |
| .com | 15,657 websites |
| .org | 2,846 websites |
| .fr | 2,409 websites |
| .de | 1,940 websites |
| .co.uk | 1,221 websites |
| .it | 1,104 websites |
| .net | 1,073 websites |
| .dk | 1,016 websites |
| .pl | 694 websites |
| .ru | 666 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jan, 2026 | CVE-2025-14804 | Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion | 14 |
| Dec, 2025 | CVE-2025-13320 | WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter | 967 |
| Dec, 2025 | CVE-2025-12529 | Cost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File Deletion | 531 |
| Nov, 2025 | CVE-2025-11451 | Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read | 2,052 |
| Oct, 2025 | CVE-2025-11738 | Media Library Assistant <= 3.29 - Unauthenticated Limited File Read | 27 |
| Oct, 2025 | CVE-2025-10494 | Motors – Car Dealership & Classified Listings Plugin <= 1.4.89 - Authenticated (Subscriber+) Arbitrary File Deletion | 219 |
| Sep, 2025 | CVE-2025-8422 | Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read | 2 |
| Jul, 2025 | CVE-2025-5393 | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Deletion | 887 |
| Jul, 2025 | CVE-2025-6691 | SureForms – Drag and Drop Form Builder for WordPress <= 1.7.3 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Submission Deletion | 210 |
| Jul, 2025 | CVE-2025-6463 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion | 18,919 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Jul, 2025 | CVE-2025-6463 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion | 18,919 |
| Jan, 2025 | CVE-2024-12267 | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion | 5,064 |
| Sep, 2024 | CVE-2024-8517 | SPIP Bigup Multipart File Upload OS Command Injection | 4,508 |
| Dec, 2024 | CVE-2024-12875 | Easy Digital Downloads <= 3.3.2 - Authenticated (Admin+) Arbitrary File Download | 4,120 |
| Sep, 2023 | CVE-2023-36764 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | 2,291 |
| Nov, 2025 | CVE-2025-11451 | Auto Amazon Links – Amazon Associates Affiliate Plugin <= 5.4.3 - Unauthenticated Arbitrary File Read | 2,052 |
| Dec, 2025 | CVE-2025-13320 | WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter | 967 |
| Jul, 2025 | CVE-2025-5393 | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Deletion | 887 |
| May, 2025 | CVE-2025-3419 | Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read | 543 |
| Dec, 2025 | CVE-2025-12529 | Cost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File Deletion | 531 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.****.com | *** | ||
| ********.com | *,*** | ||
| ***************.eu | *,*** | ||
| ***.int | *,*** | ||
| ********.com | *,*** | ||
| *************.com | *,*** | ||
| ********.org | *,*** | ||
| *********.com | *,*** | ||
| ****.**.gov | *,*** | ||
| ***************.org | *,*** |