CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,276 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 81 of 86
- CVE-2026-22799HIGHCVSS 8.8EG 8.82026-01-12
Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and con…
- CVE-2026-23499MEDIUMCVSS 5.4EG 5.42026-01-21
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing…
- CVE-2026-2354HIGHCVSS 8.8EG 8.82026-07-11
The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_…
- CVE-2026-23636HIGHCVSS 7.2EG 7.22026-03-25
Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an Unrestricted Upload of File with Dangerous Type due to a missing validation. Upgrade Kitew…
- CVE-2026-23697HIGHCVSS 8.8EG 8.82026-07-07
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing t…
- CVE-2026-23698HIGHCVSS 7.2EG 7.22026-07-07
Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP files by submitting a crafted zip archive through t…
- CVE-2026-23704MEDIUMCVSS 6.5EG 6.52026-02-04
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are En…
- CVE-2026-23802CRITICALCVSS 9.1EG 9.12026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.
- CVE-2026-24010HIGHCVSS 8.0EG 8.02026-01-22
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a mali…
- CVE-2026-24014CRITICALCVSS 9.8EG 9.82026-07-06
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an…
- CVE-2026-24034MEDIUMCVSS 5.4EG 5.42026-01-22
Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo up…
- CVE-2026-24673MEDIUMCVSS 5.3EG 4.32026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding …
- CVE-2026-24727CRITICALCVSS 9.3EG 9.32026-07-24
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute a…
- CVE-2026-24729CRITICALCVSS 10.0EG 10.02026-01-30
An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.
- CVE-2026-24769CRITICALCVSS 9.0EG 9.02026-01-28
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload malicious SVG files c…
- CVE-2026-24815CRITICALCVSS 10.0EG 10.02026-01-27
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFi…
- CVE-2026-24897CRITICALCVSS 8.8EG 10.02026-01-28
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when cr…
- CVE-2026-24960CRITICALCVSS 9.9EG 9.92026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.
- CVE-2026-25056HIGHCVSS 8.8EG 8.82026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files …
- CVE-2026-25099HIGHCVSS 8.8EG 8.82026-03-27
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
- CVE-2026-25200CRITICALCVSS 9.8EG 9.82026-02-02
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.
- CVE-2026-25201HIGHCVSS 8.8EG 8.82026-02-02
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.
- CVE-2026-25413CRITICALCVSS 9.9EG 9.92026-03-25
Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18.
- CVE-2026-25446CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
- CVE-2026-2550CRITICALCVSS 9.8EG 9.82026-02-16
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit…
- CVE-2026-25510CRITICALCVSS 8.8EG 9.92026-02-03
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote …
- CVE-2026-25648HIGHCVSS 8.7EG 8.72026-02-23
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device …
- CVE-2026-25923CRITICALCVSS 9.1EG 9.12026-02-09
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a mali…
- CVE-2026-2665MEDIUMCVSS 6.3EG 6.32026-02-18
A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument…
- CVE-2026-2666MEDIUMCVSS 7.2EG 4.72026-02-18
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestric…
- CVE-2026-26746HIGHCVSS 8.8EG 8.82026-02-20
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chain…
- CVE-2026-2684HIGHCVSS 9.8EG 7.32026-02-19
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argumen…
- CVE-2026-26975HIGHCVSS 8.8EG 8.82026-02-20
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installatio…
- CVE-2026-26984HIGHCVSS 8.8EG 8.82026-02-25
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with suffici…
- CVE-2026-2701CRITICALCVSS 9.1EG 9.12026-04-02
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
- CVE-2026-27041CRITICALCVSS 9.9EG 9.92026-06-17
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
- CVE-2026-27043HIGHCVSS 7.2EG 7.22026-03-19
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a before 7.7.6.
- CVE-2026-27064CRITICALCVSS 9.1EG 9.12026-07-23
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- CVE-2026-27067CRITICALCVSS 9.1EG 9.12026-03-19
Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through <= 1.3.1.
- CVE-2026-27146MEDIUMCVSS 4.5EG 4.52026-02-21
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file …
- CVE-2026-27419CRITICALCVSS 9.9EG 9.92026-07-02
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
- CVE-2026-2743CRITICALCVSS 9.8EG 9.82026-03-05
Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before
- CVE-2026-27540CRITICALCVSS 9.0EG 9.02026-03-19
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Captur…
- CVE-2026-27605MEDIUMCVSS 5.4EG 5.42026-03-06
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.4, the application allows uploading files (project logos) without validating the file type …
- CVE-2026-27636HIGHCVSS 8.8EG 8.82026-02-25
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. On Apache ser…
- CVE-2026-27891HIGHCVSS 7.2EG 7.22026-05-18
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives.…
- CVE-2026-27947HIGHCVSS 8.8EG 8.82026-02-27
Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnera…
- CVE-2026-28114CRITICALCVSS 9.1EG 9.12026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.
- CVE-2026-28133HIGHCVSS 8.5EG 8.52026-03-05
Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.14.
- CVE-2026-28270HIGHCVSS 7.2EG 7.22026-02-27
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →