CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,472 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 86 of 90
- CVE-2026-50124HIGHCVSS 7.1EG 7.12026-07-15
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, a…
- CVE-2026-50768CRITICALCVSS 8.8EG 9.82026-08-17
File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.
- CVE-2026-50873CRITICALCVSS 9.8EG 9.82026-06-15
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
- CVE-2026-50894CRITICALCVSS 9.8EG 9.82026-09-04
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file …
- CVE-2026-5181MEDIUMCVSS 6.3EG 6.32026-03-31
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argumen…
- CVE-2026-5261HIGHCVSS 7.3EG 7.32026-04-01
A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argument File leads to unrestricted upload. It …
- CVE-2026-52705CRITICALCVSS 9.0EG 9.02026-06-17
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
- CVE-2026-53593HIGHCVSS 8.8EG 8.82026-07-20
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht…
- CVE-2026-53599HIGHCVSS 7.5EG 7.52026-07-31
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PH…
- CVE-2026-5364HIGHCVSS 8.1EG 8.12026-04-24
The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.1.3. This is due to the plugin extracting the file extension before sanitization occurs and al…
- CVE-2026-53649CRITICALCVSS 9.6EG 9.62026-07-08
Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safeliste…
- CVE-2026-53691HIGHCVSS 8.6EG 8.62026-06-30
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fails to validate fil…
- CVE-2026-53724LOWCVSS 2.1EG 2.12026-06-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to …
- CVE-2026-53787CRITICALCVSS 9.8EG 9.82026-06-12
Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of…
- CVE-2026-53909MEDIUMCVSS 6.5EG 6.52026-07-01
MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypassed. An authorized, low-privileged attacker can upload files with arbitrary types to the ser…
- CVE-2026-53948MEDIUMCVSS 5.4EG 5.42026-06-24
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacke…
- CVE-2026-54087HIGHCVSS 7.6EG 7.62026-07-14
EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline sam…
- CVE-2026-5411HIGHCVSS 8.8EG 8.82026-06-05
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability c…
- CVE-2026-54177MEDIUMCVSS 6.6EG 6.62026-08-20
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFile…
- CVE-2026-54179MEDIUMCVSS 4.4EG 4.42026-08-20
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/Sing…
- CVE-2026-54414CRITICALCVSS 9.8EG 9.82026-06-19
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by Fol…
- CVE-2026-54416HIGHCVSS 7.2EG 7.22026-08-05
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cg…
- CVE-2026-54567HIGHCVSS 7.5EG 7.52026-07-17
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helpe…
- CVE-2026-54611MEDIUMCVSS 5.5EG 5.52026-09-08
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possibl…
- CVE-2026-5472MEDIUMCVSS 6.3EG 6.32026-04-03
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handle…
- CVE-2026-5482CRITICALCVSS 9.3EG 9.32026-06-15
Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assi…
- CVE-2026-5524CRITICALCVSS 9.8EG 9.82026-07-02
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to... The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and i…
- CVE-2026-55419MEDIUMCVSS 5.3EG 5.32026-08-25
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/sounds/upload endpoint implemented by the upload_sound method in src/reachy_mini/daemon/app/routers/media.py without au…
- CVE-2026-5546MEDIUMCVSS 6.3EG 6.32026-04-05
A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiat…
- CVE-2026-55633HIGHCVSS 8.7EG 8.72026-07-07
DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontMa…
- CVE-2026-55676HIGHCVSS 8.8EG 8.82026-08-11
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-lis…
- CVE-2026-5573CRITICALCVSS 9.8EG 9.82026-04-05
A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipulation of the argument cwd can lead to unrestricted upload. The attack can be launched remo…
- CVE-2026-5576MEDIUMCVSS 4.7EG 4.72026-04-05
A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functionality of the file save_emp.php of the component Add Employee Page. This manipulation causes unrestricted upload. Remo…
- CVE-2026-55778LOWCVSS 2.1EG 2.12026-06-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-st…
- CVE-2026-56027CRITICALCVSS 9.9EG 9.92026-06-26
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
- CVE-2026-56058CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
- CVE-2026-56059CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
- CVE-2026-56290CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-29
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
- CVE-2026-56291CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-09
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
- CVE-2026-56414HIGHCVSS 7.2EG 7.22026-06-26
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This de…
- CVE-2026-56590MEDIUMCVSS 6.4EG 6.42026-09-18
HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a complet…
- CVE-2026-5670MEDIUMCVSS 6.3EG 6.32026-04-06
A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipula…
- CVE-2026-56702HIGHCVSS 8.8EG 8.82026-08-25
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can uploa…
- CVE-2026-5704MEDIUMCVSS 5.5EG 5.52026-04-06
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, poten…
- CVE-2026-5718HIGHCVSS 8.1EG 8.12026-04-17
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom black…
- CVE-2026-57311MEDIUMCVSS 5.3EG 5.32026-07-20
Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has on…
- CVE-2026-57581MEDIUMCVSS 5.3EG 5.32026-09-14
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMidd…
- CVE-2026-57658CRITICALCVSS 9.1EG 9.12026-06-26
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
- CVE-2026-57700CRITICALCVSS 10.0EG 10.02026-06-25
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
- CVE-2026-57710CRITICALCVSS 9.9EG 9.92026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →