RSFiles! up to 1.17.11 let an anonymous visitor upload a PHP file and run code on your server. I found it, reported it privately, and the fix is out. Update to 1.17.12 now.