Unauthenticated Arbitrary File Upload in SigmaForms Pro by Patchstack
CVE-2026-52705

9CRITICAL

What is CVE-2026-52705?

SigmaForms Pro – AI Generated Forms versions up to 1.4.5 contain a vulnerability that allows unauthenticated users to upload arbitrary files. This could lead to potential exploitation, where attackers might plant malicious files on the server, compromising data integrity and system security. Users are advised to upgrade to the latest versions to mitigate risks associated with this vulnerability.

Affected Version(s)

SigmaForms Pro – AI Generated Forms <= 1.4.5

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.