← Vulnerability feed

Vulnerability record · CVE-2015-6967 · published 16 September 2015

CVE-2015-6967: Nibbleblog My Image plugin unrestricted file upload enables code execution

Nibbleblog · Nibbleblog

The My Image plugin in Nibbleblog before 4.0.5 permits uploading files with executable extensions without proper validation. An attacker with administrator access can upload a PHP file and then request it directly, achieving remote code execution on the server.

6.5 CVSS 2.0 Medium EPSS 49% · top 1.1%
6.5CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAlthough exploitation requires administrator privileges, public exploits exist and EPSS is very high, making it a significant risk for exposed Nibbleblog instances.

What it is

The My Image plugin in Nibbleblog before 4.0.5 permits uploading files with executable extensions without proper validation. An attacker with administrator access can upload a PHP file and then request it directly, achieving remote code execution on the server.

Impact

An attacker gains arbitrary code execution with the privileges of the web server, allowing full compromise of the Nibbleblog installation and potentially the underlying host.

Attack surface

The vulnerability is reached over the network via the My Image plugin upload functionality. It requires authenticated administrator access; no user interaction beyond the upload and subsequent direct request is needed.

Exploitation

Public exploit references are available, and EPSS indicates a high probability of exploitation activity (0.49308, 98.8th percentile). The CVE is not listed in CISA KEV.

What to do

  • Upgrade Nibbleblog to version 4.0.5 or later, which fixes the unrestricted file upload.
  • Restrict administrator access to trusted networks and enforce strong authentication.
  • Disable or remove the My Image plugin if it is not required.
  • Configure the web server to prevent execution of uploaded files in content/private/plugins/my_image/.
  • Monitor and audit file uploads for executable extensions.

Detection

  • Monitor web server logs for POST requests to the My Image plugin upload endpoint followed by GET requests to content/private/plugins/my_image/image.php.
  • Alert on the creation of files with executable extensions (e.g., .php) in the content/private/plugins/my_image/ directory.
  • Use file integrity monitoring to detect unexpected changes in plugin directories.
  • Review administrator account activity for suspicious uploads or logins from unusual locations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6967 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2015-6967), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.