CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,472 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 88 of 90
- CVE-2026-68899HIGHCVSS 8.7EG 8.72026-08-19
Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was …
- CVE-2026-6933HIGHCVSS 8.8EG 8.82026-06-16
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before p…
- CVE-2026-6960CRITICALCVSS 9.8EG 9.82026-05-21
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes…
- CVE-2026-7043MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The ex…
- CVE-2026-7044MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has be…
- CVE-2026-70558CRITICALCVSS 9.8EG 9.82026-08-06
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the …
- CVE-2026-7107MEDIUMCVSS 6.3EG 6.32026-04-27
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to b…
- CVE-2026-7133MEDIUMCVSS 4.7EG 4.72026-04-27
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument directory causes unrestricted upload. The attack can be initia…
- CVE-2026-7134MEDIUMCVSS 4.7EG 4.72026-04-27
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument image leads to unrestricted upload. The attack can be launc…
- CVE-2026-71434MEDIUMCVSS 5.3EG 5.32026-08-06
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could uplo…
- CVE-2026-71620HIGHCVSS 8.1EG 8.12026-09-04
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file
- CVE-2026-71805CRITICALCVSS 9.8EG 9.82026-09-09
An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app…
- CVE-2026-7238MEDIUMCVSS 4.7EG 4.72026-04-28
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of t…
- CVE-2026-72557HIGHCVSS 8.8EG 8.82026-08-11
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and …
- CVE-2026-72592CRITICALCVSS 9.8EG 9.82026-08-10
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no …
- CVE-2026-72762HIGHCVSS 8.8EG 8.82026-08-11
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able …
- CVE-2026-73373CRITICALCVSS 9.8EG 9.82026-08-18
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
- CVE-2026-7393MEDIUMCVSS 4.7EG 4.72026-04-29
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img res…
- CVE-2026-73996CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
- CVE-2026-74014CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
- CVE-2026-74016CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
- CVE-2026-74018CRITICALCVSS 9.9EG 9.92026-08-20
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
- CVE-2026-74767HIGHCVSS 8.7EG 8.72026-08-15
Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enforci…
- CVE-2026-74803CRITICALCVSS 10.0EG 10.02026-08-19
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
- CVE-2026-74845HIGHCVSS 8.8EG 8.82026-08-17
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on th…
- CVE-2026-7490HIGHCVSS 7.2EG 7.22026-05-02
CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- CVE-2026-75169HIGHCVSS 8.8EG 8.82026-09-04
An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths.
- CVE-2026-75327CRITICALCVSS 9.8EG 9.82026-08-26
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
- CVE-2026-75331MEDIUMCVSS 4.6EG 4.62026-08-26
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTM…
- CVE-2026-7537HIGHCVSS 7.2EG 7.22026-06-06
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation bein…
- CVE-2026-75496HIGHCVSS 7.2EG 7.22026-08-25
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable …
- CVE-2026-7578MEDIUMCVSS 4.7EG 4.72026-05-01
A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unre…
- CVE-2026-75865CRITICALCVSS 9.8EG 9.82026-09-01
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined…
- CVE-2026-75949CRITICALCVSS 10.0EG 10.02026-08-19
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enfo…
- CVE-2026-76174CRITICALCVSS 9.4EG 9.42026-09-03
Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or …
- CVE-2026-76552HIGHCVSS 8.8EG 8.82026-09-16
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, …
- CVE-2026-7673MEDIUMCVSS 4.7EG 4.72026-05-03
A vulnerability was detected in crmeb_java up to 1.3.4. This vulnerability affects unknown code of the file crmeb/crmeb-service/src/main/java/com/zbkj/service/service/impl/UploadServiceImpl.java of the component Admin Upload. Performing a …
- CVE-2026-76800MEDIUMCVSS 6.3EG 6.32026-08-20
A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the argument uploadfile can lead to unrestricted upload. The atta…
- CVE-2026-7696MEDIUMCVSS 6.3EG 6.32026-05-03
A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File res…
- CVE-2026-76995MEDIUMCVSS 4.7EG 4.72026-08-20
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted up…
- CVE-2026-77018HIGHCVSS 8.8EG 8.82026-08-27
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as s…
- CVE-2026-7711HIGHCVSS 7.3EG 7.32026-05-04
A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted…
- CVE-2026-7732MEDIUMCVSS 6.3EG 6.32026-05-04
A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. T…
- CVE-2026-7733HIGHCVSS 7.3EG 7.32026-05-04
A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.php of the component Frontend Chunked Upload Endpoint. This manipulation of the argument F…
- CVE-2026-77681MEDIUMCVSS 6.3EG 6.32026-08-21
A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The at…
- CVE-2026-77929HIGHCVSS 8.8EG 8.82026-09-18
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::m…
- CVE-2026-77991CRITICALCVSS 9.4EG 9.42026-08-27
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.
- CVE-2026-78078HIGHCVSS 8.9EG 8.92026-08-31
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster ext…
- CVE-2026-78088HIGHCVSS 8.8EG 8.82026-09-16
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…
- CVE-2026-78202HIGHCVSS 7.3EG 7.32026-08-24
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →