CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,472 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 87 of 90
- CVE-2026-57719CRITICALCVSS 10.0EG 10.02026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
- CVE-2026-57827CRITICALCVSS 9.8EG 9.82026-07-11
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full …
- CVE-2026-57828HIGHCVSS 8.8EG 8.82026-07-11
Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable f…
- CVE-2026-58409CRITICALCVSS 9.1EG 9.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. The …
- CVE-2026-58428MEDIUMCVSS 6.5EG 6.52026-07-21
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-58480CRITICALCVSS 9.8EG 9.82026-07-08
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function ex…
- CVE-2026-58654MEDIUMCVSS 4.3EG 4.32026-07-08
The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType…
- CVE-2026-60032CRITICALCVSS 9.4EG 9.42026-07-20
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. poly…
- CVE-2026-61424CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-61448LOWCVSS 2.1EG 2.12026-07-11
Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-…
- CVE-2026-61457HIGHCVSS 8.8EG 8.82026-07-15
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PAT…
- CVE-2026-6147HIGHCVSS 8.8EG 8.82026-08-05
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated a…
- CVE-2026-61524HIGHCVSS 7.2EG 7.22026-08-03
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a…
- CVE-2026-61900CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-6211HIGHCVSS 8.7EG 8.72026-06-12
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.
- CVE-2026-6249HIGHCVSS 8.8EG 8.82026-04-20
Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary operating system commands by uploading a PHP webshell with a .phtml extension. Attackers …
- CVE-2026-6257CRITICALCVSS 9.1EG 9.12026-04-20
Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php o…
- CVE-2026-6261HIGHCVSS 8.8EG 8.82026-05-05
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directo…
- CVE-2026-6271CRITICALCVSS 9.8EG 9.82026-05-14
The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated att…
- CVE-2026-63048CRITICALCVSS 9.4EG 9.42026-07-22
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
- CVE-2026-63223CRITICALCVSS 9.8EG 9.82026-07-31
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an …
- CVE-2026-63227CRITICALCVSS 9.9EG 9.92026-07-29
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
- CVE-2026-63228LOWCVSS 2.6EG 2.62026-07-29
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the ser…
- CVE-2026-63429HIGHCVSS 8.6EG 8.62026-07-20
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous intern…
- CVE-2026-6489MEDIUMCVSS 6.3EG 6.32026-04-17
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation …
- CVE-2026-64960HIGHCVSS 8.7EG 8.72026-08-20
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored in a web-accessible location before their content is validated. An authenticated a…
- CVE-2026-6518HIGHCVSS 8.8EG 8.82026-04-18
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. …
- CVE-2026-65455CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-65461CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-6555CRITICALCVSS 9.8EG 9.82026-05-20
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension an…
- CVE-2026-6561MEDIUMCVSS 4.7EG 4.72026-04-19
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The …
- CVE-2026-65640HIGHCVSS 8.8EG 8.82026-08-17
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_fil…
- CVE-2026-65885HIGHCVSS 8.8EG 8.82026-07-29
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the…
- CVE-2026-65939MEDIUMCVSS 6.8EG 6.82026-08-12
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- CVE-2026-6596HIGHCVSS 7.3EG 7.32026-04-20
A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results i…
- CVE-2026-65986HIGHCVSS 8.5EG 8.52026-08-04
CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to …
- CVE-2026-6602HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic resul…
- CVE-2026-66270HIGHCVSS 7.2EG 7.22026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to …
- CVE-2026-66271HIGHCVSS 7.2EG 7.22026-08-14
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to …
- CVE-2026-6650MEDIUMCVSS 4.7EG 4.72026-04-20
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may…
- CVE-2026-66600CRITICALCVSS 9.1EG 9.12026-08-20
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
- CVE-2026-66627CRITICALCVSS 9.9EG 9.92026-08-18
Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.
- CVE-2026-66665CRITICALCVSS 10.0EG 10.02026-08-06
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-6692HIGHCVSS 8.8EG 8.82026-05-07
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possibl…
- CVE-2026-67206HIGHCVSS 8.8EG 8.82026-07-30
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and sav…
- CVE-2026-67243HIGHCVSS 7.2EG 7.22026-08-04
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.
- CVE-2026-67678CRITICALCVSS 9.8EG 9.82026-08-17
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
- CVE-2026-67688CRITICALCVSS 9.8EG 9.82026-08-06
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- CVE-2026-6835MEDIUMCVSS 6.1EG 6.12026-04-22
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
- CVE-2026-6885CRITICALCVSS 9.8EG 9.82026-04-23
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code e…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →