CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,555 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 9 of 92
- CVE-2026-13249CRITICALCVSS 9.8EG 9.82026-09-24
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authe…
- CVE-2026-93352CRITICALCVSS 9.8EG 9.82026-09-23
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 in…
- CVE-2026-82187CRITICALCVSS 9.8EG 9.82026-09-21
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to u…
- CVE-2026-84434CRITICALCVSS 9.8EG 9.82026-09-19
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persiste…
- CVE-2026-45140CRITICALCVSS 9.8EG 9.82026-09-17
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, co…
- CVE-2026-87796CRITICALCVSS 9.8EG 9.82026-09-17
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload…
- CVE-2026-81240CRITICALCVSS 9.8EG 9.82026-09-15
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to R…
- CVE-2026-81239CRITICALCVSS 9.8EG 9.82026-09-15
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to R…
- CVE-2026-81236CRITICALCVSS 9.8EG 9.82026-09-15
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to R…
- CVE-2026-84171CRITICALCVSS 9.8EG 9.82026-09-12
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and exec…
- CVE-2026-81402CRITICALCVSS 9.8EG 9.82026-09-12
The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to …
- CVE-2026-8778CRITICALCVSS 9.8EG 9.82026-09-11
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versio…
- CVE-2026-18351CRITICALCVSS 9.8EG 9.82026-09-10
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validat…
- CVE-2026-71805CRITICALCVSS 9.8EG 9.82026-09-09
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app…
- CVE-2026-44402CRITICALCVSS 9.8EG 9.82026-09-04
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archi…
- CVE-2026-50894CRITICALCVSS 9.8EG 9.82026-09-04
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file …
- CVE-2025-9314CRITICALCVSS 9.8EG 9.82026-09-02
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
- CVE-2026-84637CRITICALCVSS 9.8EG 9.82026-09-01
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachme…
- CVE-2026-75865CRITICALCVSS 9.8EG 9.82026-09-01
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined…
- CVE-2026-14494CRITICALCVSS 9.8EG 9.82026-08-29
The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capab…
- CVE-2026-18080CRITICALCVSS 9.8EG 9.82026-08-26
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing…
- CVE-2026-80235CRITICALCVSS 9.8EG 9.82026-08-26
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- CVE-2025-61165CRITICALCVSS 9.8EG 9.82026-08-26
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
- CVE-2026-75327CRITICALCVSS 9.8EG 9.82026-08-26
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
- CVE-2026-16286CRITICALCVSS 9.8EG 9.82026-08-25
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This iss…
- CVE-2026-73373CRITICALCVSS 9.8EG 9.82026-08-18
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
- CVE-2026-73996CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
- CVE-2026-15748CRITICALCVSS 9.8EG 9.82026-08-18
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, wher…
- CVE-2026-67678CRITICALCVSS 9.8EG 9.82026-08-17
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
- CVE-2026-16098CRITICALCVSS 9.8EG 9.82026-08-16
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Conte…
- CVE-2026-49827CRITICALCVSS 9.8EG 9.82026-08-13
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Co…
- CVE-2026-18391CRITICALCVSS 9.8EG 9.82026-08-12
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can…
- CVE-2026-15039CRITICALCVSS 9.8EG 9.82026-08-12
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.
- CVE-2026-72592CRITICALCVSS 9.8EG 9.82026-08-10
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no …
- CVE-2026-19089CRITICALCVSS 9.8EG 9.82026-08-10
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthentic…
- CVE-2022-4995CRITICALCVSS 9.8EG 9.82026-08-07
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to…
- CVE-2026-70558CRITICALCVSS 9.8EG 9.82026-08-06
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the …
- CVE-2026-67688CRITICALCVSS 9.8EG 9.82026-08-06
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- CVE-2026-14175CRITICALCVSS 9.8EG 9.82026-08-04
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resourc…
- CVE-2026-16618CRITICALCVSS 9.8EG 9.82026-08-04
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unaut…
- CVE-2026-16250CRITICALCVSS 9.8EG 9.82026-08-03
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reacha…
- CVE-2026-16060CRITICALCVSS 9.8EG 9.82026-08-03
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file…
- CVE-2026-12872CRITICALCVSS 9.8EG 9.82026-08-03
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary file…
- CVE-2026-21662CRITICALCVSS 9.8EG 9.82026-07-31
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
- CVE-2026-14483CRITICALCVSS 9.8EG 9.82026-07-31
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload fu…
- CVE-2026-63223CRITICALCVSS 9.8EG 9.82026-07-31
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an …
- CVE-2026-16610CRITICALCVSS 9.8EG 9.82026-07-30
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a pub…
- CVE-2026-13714CRITICALCVSS 9.8EG 9.82026-07-27
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardc…
- CVE-2026-14282CRITICALCVSS 9.8EG 9.82026-07-23
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficie…
- CVE-2026-36669CRITICALCVSS 9.8EG 9.82026-07-17
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →