CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,394 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 87 of 88
- CVE-2026-63227CRITICALCVSS 9.9EG 9.92026-07-29
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
- CVE-2026-63228LOWCVSS 2.6EG 2.62026-07-29
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the ser…
- CVE-2026-63429HIGHCVSS 8.6EG 8.62026-07-20
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous intern…
- CVE-2026-6489MEDIUMCVSS 6.3EG 6.32026-04-17
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation …
- CVE-2026-64960HIGHCVSS 8.7EG 8.72026-08-20
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated a…
- CVE-2026-6518HIGHCVSS 8.8EG 8.82026-04-18
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. …
- CVE-2026-65455CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-65461CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-6555CRITICALCVSS 9.8EG 9.82026-05-20
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension an…
- CVE-2026-6561MEDIUMCVSS 4.7EG 4.72026-04-19
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The …
- CVE-2026-65640HIGHCVSS 8.8EG 8.82026-08-17
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_fil…
- CVE-2026-65885HIGHCVSS 8.8EG 8.82026-07-29
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the…
- CVE-2026-65939MEDIUMCVSS 6.8EG 6.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- CVE-2026-6596HIGHCVSS 7.3EG 7.32026-04-20
A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results i…
- CVE-2026-65986HIGHCVSS 8.5EG 8.52026-08-04
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to …
- CVE-2026-6602HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic resul…
- CVE-2026-66270HIGHCVSS 7.2EG 7.22026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to …
- CVE-2026-66271HIGHCVSS 7.2EG 7.22026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to …
- CVE-2026-6650MEDIUMCVSS 4.7EG 4.72026-04-20
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may…
- CVE-2026-66600CRITICALCVSS 9.1EG 9.12026-08-20
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
- CVE-2026-66627CRITICALCVSS 9.9EG 9.92026-08-18
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
- CVE-2026-66665CRITICALCVSS 10.0EG 10.02026-08-06
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-6692HIGHCVSS 8.8EG 8.82026-05-07
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possibl…
- CVE-2026-67206HIGHCVSS 8.8EG 8.82026-07-30
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and sav…
- CVE-2026-67243HIGHCVSS 7.2EG 7.22026-08-04
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.
- CVE-2026-67678CRITICALCVSS 9.8EG 9.82026-08-17
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
- CVE-2026-67688CRITICALCVSS 9.8EG 9.82026-08-06
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- CVE-2026-6835MEDIUMCVSS 6.1EG 6.12026-04-22
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
- CVE-2026-6885CRITICALCVSS 9.8EG 9.82026-04-23
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code e…
- CVE-2026-68899HIGHCVSS 8.7EG 8.72026-08-19
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was …
- CVE-2026-6933HIGHCVSS 8.8EG 8.82026-06-16
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before p…
- CVE-2026-6960CRITICALCVSS 9.8EG 9.82026-05-21
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes…
- CVE-2026-7043MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The ex…
- CVE-2026-7044MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has be…
- CVE-2026-70558CRITICALCVSS 9.8EG 9.82026-08-06
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the …
- CVE-2026-7107MEDIUMCVSS 6.3EG 6.32026-04-27
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to b…
- CVE-2026-7133MEDIUMCVSS 4.7EG 4.72026-04-27
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initia…
- CVE-2026-7134MEDIUMCVSS 4.7EG 4.72026-04-27
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launc…
- CVE-2026-71434MEDIUMCVSS 5.3EG 5.32026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could uplo…
- CVE-2026-7238MEDIUMCVSS 4.7EG 4.72026-04-28
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of t…
- CVE-2026-72557HIGHCVSS 8.8EG 8.82026-08-11
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and …
- CVE-2026-72592CRITICALCVSS 9.8EG 9.82026-08-10
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no …
- CVE-2026-72762HIGHCVSS 7.7EG 7.72026-08-11
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able …
- CVE-2026-73373HIGHCVSS 8.9EG 8.92026-08-18
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
- CVE-2026-7393MEDIUMCVSS 4.7EG 4.72026-04-29
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img res…
- CVE-2026-73996CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
- CVE-2026-74014CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
- CVE-2026-74016CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
- CVE-2026-74018CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
- CVE-2026-74767HIGHCVSS 8.7EG 8.72026-08-15
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforci…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →