CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,555 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 11 of 92
- CVE-2026-3187CRITICALCVSS 9.8EG 9.82026-02-25
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoint. Such manipulation leads to unrestric…
- CVE-2026-3025CRITICALCVSS 9.8EG 9.82026-02-23
A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the arg…
- CVE-2026-1405CRITICALCVSS 9.8EG 9.82026-02-19
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for …
- CVE-2026-2684CRITICALCVSS 9.8EG 9.82026-02-19
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argumen…
- CVE-2026-2550CRITICALCVSS 9.8EG 9.82026-02-16
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit…
- CVE-2026-1306CRITICALCVSS 9.8EG 9.82026-02-14
The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthen…
- CVE-2026-1358CRITICALCVSS 9.8EG 9.82026-02-12
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.
- CVE-2025-14014CRITICALCVSS 9.8EG 9.82026-02-12
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This …
- CVE-2026-1357CRITICALCVSS 9.8EG 9.82026-02-11
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption…
- CVE-2026-2183CRITICALCVSS 9.8EG 9.82026-02-08
A security vulnerability has been detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73. This affects an unknown part of the file /restructured/csv.php. The manipulation leads to unrestri…
- CVE-2026-2164CRITICALCVSS 9.8EG 9.82026-02-08
A security flaw has been discovered in detronetdip E-commerce 1.0.0. This issue affects some unknown processing of the file /seller/assets/backend/profile/addadhar.php. Performing a manipulation of the argument File results in unrestricted…
- CVE-2026-2133CRITICALCVSS 9.8EG 9.82026-02-08
A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtimage causes unrestricted upload. The attac…
- CVE-2026-2113CRITICALCVSS 9.8EG 9.82026-02-07
A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to …
- CVE-2026-1813CRITICALCVSS 9.8EG 9.82026-02-04
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the a…
- CVE-2020-37090CRITICALCVSS 9.8EG 9.82026-02-03
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code exe…
- CVE-2025-69981CRITICALCVSS 9.8EG 9.82026-02-03
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to o…
- CVE-2025-65875CRITICALCVSS 9.8EG 9.82026-02-03
An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2025-61506CRITICALCVSS 9.8EG 9.82026-02-03
An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.
- CVE-2025-66480CRITICALCVSS 9.8EG 9.82026-02-02
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAc…
- CVE-2026-25200CRITICALCVSS 9.8EG 9.82026-02-02
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.
- CVE-2025-69559CRITICALCVSS 9.8EG 9.82026-01-27
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
- CVE-2025-69565CRITICALCVSS 9.8EG 9.82026-01-27
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
- CVE-2026-1423CRITICALCVSS 9.8EG 9.82026-01-26
A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admin_pic.php. Executing a manipulation can lead to unrestricted upload. The attack may be per…
- CVE-2025-13374CRITICALCVSS 9.8EG 9.82026-01-24
The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthentica…
- CVE-2025-70457CRITICALCVSS 9.8EG 9.82026-01-23
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application pr…
- CVE-2026-1331CRITICALCVSS 9.8EG 9.82026-01-22
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- CVE-2025-55251CRITICALCVSS 9.8EG 9.82026-01-19
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.
- CVE-2026-1152CRITICALCVSS 9.8EG 9.82026-01-19
A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code Image Handler. Such manipulation of the argument codeimg leads to unrestricted upload. The…
- CVE-2026-1107CRITICALCVSS 9.8EG 9.82026-01-18
A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted u…
- CVE-2026-1061CRITICALCVSS 9.8EG 9.82026-01-17
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unres…
- CVE-2025-14894CRITICALCVSS 9.8EG 9.82026-01-16
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed…
- CVE-2025-67079CRITICALCVSS 9.8EG 9.82026-01-15
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.
- CVE-2021-47819CRITICALCVSS 9.8EG 9.82026-01-15
ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment sect…
- CVE-2021-47753CRITICALCVSS 9.8EG 9.82026-01-15
phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and exec…
- CVE-2022-50912CRITICALCVSS 9.8EG 9.82026-01-13
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.ph…
- CVE-2022-50893CRITICALCVSS 9.8EG 9.82026-01-13
VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code …
- CVE-2025-65783CRITICALCVSS 9.8EG 9.82026-01-13
An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
- CVE-2025-66802CRITICALCVSS 9.8EG 9.82026-01-12
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
- CVE-2025-15503CRITICALCVSS 9.8EG 9.82026-01-10
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argumen…
- CVE-2025-67325CRITICALCVSS 9.8EG 9.82026-01-08
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
- CVE-2019-25296CRITICALCVSS 9.8EG 9.82026-01-08
The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes…
- CVE-2026-0643CRITICALCVSS 9.8EG 9.82026-01-07
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upl…
- CVE-2025-15448CRITICALCVSS 9.8EG 9.82026-01-05
A vulnerability was found in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. This impacts the function Upload of the file src/main/java/com/macro/mall/controller/MinioController.java. The manipulation results in unres…
- CVE-2026-0577CRITICALCVSS 9.8EG 9.82026-01-04
A flaw has been found in code-projects Online Product Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /handgunner-administrator/prod.php. Executing a manipulation can lead to unrestricted uplo…
- CVE-2026-0566CRITICALCVSS 9.8EG 9.82026-01-02
A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack i…
- CVE-2024-27480CRITICALCVSS 9.8EG 9.82025-12-29
givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
- CVE-2024-25182CRITICALCVSS 9.8EG 9.82025-12-29
givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
- CVE-2025-57460CRITICALCVSS 9.8EG 9.82025-12-29
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
- CVE-2025-15228CRITICALCVSS 9.8EG 9.82025-12-29
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- CVE-2025-15226CRITICALCVSS 9.8EG 9.82025-12-29
WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →