Critical Vulnerability Information Vulnerability Identifier CVE-2025-28168 Vulnerability Description A vulnerability discovered in the Multiple File Upload component, affecting versions prior to 3.1.0. The issue lies in the lack of server-side validation for supported file extensions. Attackers can bypass this restriction by intercepting file upload requests and modifying the parameter. Additionally, file size validation is performed only on the client side, allowing attackers to tamper with client-side JavaScript code to circumvent this restriction. Vulnerability Type Unrestricted File Upload Product Vendor Multi Uploaders Affected Product Codebase Multiple File Upload prior to 3.1.0 Link Affected Component File Upload functionality prior to 3.1.0 Attack Type Remote Impact Denial of Service: true Attack Vector Attackers can intercept file upload requests (typically using proxy tools such as Burp Suite) and modify the requests to upload malicious files, such as web shells, executable scripts, or large resource-intensive files. Reference Links Component Version Component Documentation