---
id: CVE-2021-36581
title: Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload
summary: >-
  Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to
  upload any file extension to the server. The server does not verify the
  extension of the file and the tester was able to upload an aspx to the server.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: kooboo
product: kooboo_cms
affected:
  - kooboo_cms = 2.1.1.0
published: '2021-09-14'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-36581'
references:
  - url: 'https://github.com/l00neyhacker/CVE-2021-36581/'
    label: cve@mitre.org
  - url: 'http://kooboo.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/l00neyhacker/CVE-2021-36581/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0143
epssPercentile: 0.71868
ingestedAt: '2026-07-06T01:08:17.031Z'
---

## Overview

Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.

## Affected

- `kooboo_cms = 2.1.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
