CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,471 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 84 of 90
- CVE-2026-33809MEDIUMCVSS 5.3EG 5.32026-03-25
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.
- CVE-2026-34027MEDIUMCVSS 5.3EG 5.32026-06-15
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-…
- CVE-2026-34031MEDIUMCVSS 6.5EG 6.52026-06-09
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be…
- CVE-2026-3418CRITICALCVSS 9.1EG 9.12026-08-06
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated admi…
- CVE-2026-3459HIGHCVSS 8.1EG 8.12026-03-05
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3…
- CVE-2026-34735HIGHCVSS 8.7EG 8.72026-04-02
The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prior, the quickUpload() endpoint validates uploaded files by checking their MIME type (via PHP's finfo, which inspects fil…
- CVE-2026-35047CRITICALCVSS 9.8EG 9.82026-04-06
Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on t…
- CVE-2026-35164HIGHCVSS 8.8EG 8.82026-04-06
Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The me…
- CVE-2026-35174HIGHCVSS 7.2EG 7.22026-04-06
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to …
- CVE-2026-3533HIGHCVSS 8.8EG 8.82026-03-24
The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up …
- CVE-2026-3535CRITICALCVSS 9.8EG 9.82026-04-08
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is expo…
- CVE-2026-35573CRITICALCVSS 9.1EG 9.12026-04-07
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code executio…
- CVE-2026-36387MEDIUMCVSS 6.5EG 6.52026-05-07
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malic…
- CVE-2026-36669CRITICALCVSS 9.8EG 9.82026-07-17
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.
- CVE-2026-36722MEDIUMCVSS 5.4EG 5.42026-06-09
An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2026-37430HIGHCVSS 7.3EG 7.32026-05-13
An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2026-3748HIGHCVSS 8.8EG 8.82026-03-08
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the component SVG File Handler. Performing a mani…
- CVE-2026-3749HIGHCVSS 8.8EG 8.82026-03-08
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestService.java of the component SVG File Handler. Execu…
- CVE-2026-37748HIGHCVSS 7.2EG 7.22026-04-21
Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content valid…
- CVE-2026-3797HIGHCVSS 8.8EG 8.82026-03-09
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File.java. The manipulation of t…
- CVE-2026-3800HIGHCVSS 8.8EG 8.82026-03-09
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The atta…
- CVE-2026-3844CRITICALCVSS 9.8EG 9.82026-04-23
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthen…
- CVE-2026-38526CRITICALCVSS 9.9EG 9.92026-04-14
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2026-38751HIGHCVSS 7.2EG 7.22026-05-04
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
- CVE-2026-3891CRITICALCVSS 9.8EG 9.82026-03-13
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and inc…
- CVE-2026-38991HIGHCVSS 8.8EG 8.82026-04-29
Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary…
- CVE-2026-39292HIGHCVSS 7.3EG 7.32026-05-29
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exi…
- CVE-2026-39527MEDIUMCVSS 5.4EG 5.42026-06-15
Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
- CVE-2026-39589CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
- CVE-2026-39591CRITICALCVSS 9.9EG 9.92026-06-15
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
- CVE-2026-39598HIGHCVSS 8.0EG 8.02026-06-17
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
- CVE-2026-39931HIGHCVSS 7.2EG 7.22026-08-03
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the ap…
- CVE-2026-40040HIGHCVSS 8.8EG 8.82026-04-13
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files …
- CVE-2026-40262HIGHCVSS 8.7EG 8.72026-04-17
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection for content type, which does not identify text-based formats such…
- CVE-2026-40412CRITICALCVSS 9.8EG 10.02026-05-26
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
- CVE-2026-40484CRITICALCVSS 9.1EG 9.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document roo…
- CVE-2026-40487HIGHCVSS 8.9EG 8.92026-04-18
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type`…
- CVE-2026-40488HIGHCVSS 8.8EG 8.82026-04-20
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product cust…
- CVE-2026-40548MEDIUMCVSS 6.4EG 6.42026-06-01
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on …
- CVE-2026-40746CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
- CVE-2026-40747CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
- CVE-2026-40748CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- CVE-2026-40749CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- CVE-2026-40750CRITICALCVSS 9.9EG 9.92026-06-16
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
- CVE-2026-40772CRITICALCVSS 10.0EG 10.02026-06-15
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
- CVE-2026-41269HIGHCVSS 7.1EG 7.12026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker u…
- CVE-2026-41517UnratedEG not assessed2026-05-08
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor install…
- CVE-2026-41587HIGHCVSS 8.6EG 8.62026-05-07
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated…
- CVE-2026-4191HIGHCVSS 7.3EG 7.32026-03-16
A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be …
- CVE-2026-41937HIGHCVSS 7.2EG 7.22026-05-14
Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containin…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →