CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,276 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 83 of 86
- CVE-2026-35573CRITICALCVSS 9.1EG 9.12026-04-07
ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code executio…
- CVE-2026-36387MEDIUMCVSS 6.5EG 6.52026-05-07
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malic…
- CVE-2026-36669CRITICALCVSS 9.8EG 9.82026-07-17
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.
- CVE-2026-36722MEDIUMCVSS 5.4EG 5.42026-06-09
An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2026-37430HIGHCVSS 7.3EG 7.32026-05-13
An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2026-3748MEDIUMCVSS 8.8EG 6.32026-03-08
A security flaw has been discovered in Bytedesk up to 1.3.9. This affects the function uploadFile of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestController.java of the component SVG File Handler. Performing a mani…
- CVE-2026-3749MEDIUMCVSS 8.8EG 6.32026-03-08
A weakness has been identified in Bytedesk up to 1.3.9. This vulnerability affects the function handleFileUpload of the file source-code/src/main/java/com/bytedesk/core/upload/UploadRestService.java of the component SVG File Handler. Execu…
- CVE-2026-37748HIGHCVSS 7.2EG 7.22026-04-21
Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content valid…
- CVE-2026-3797MEDIUMCVSS 8.8EG 6.32026-03-09
A security vulnerability has been detected in Tiandy Video Surveillance System 视频监控平台 7.17.0. The impacted element is the function uploadFile of the file /src/com/tiandy/easy7/core/rest/CLS_REST_File.java. The manipulation of t…
- CVE-2026-3800MEDIUMCVSS 8.8EG 6.32026-03-09
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The atta…
- CVE-2026-3844CRITICALCVSS 9.8EG 9.82026-04-23
The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthen…
- CVE-2026-38526CRITICALCVSS 9.9EG 9.92026-04-14
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2026-38751HIGHCVSS 7.2EG 7.22026-05-04
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
- CVE-2026-3891CRITICALCVSS 9.8EG 9.82026-03-13
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and inc…
- CVE-2026-38991HIGHCVSS 8.8EG 8.82026-04-29
Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary…
- CVE-2026-39292HIGHCVSS 7.3EG 7.32026-05-29
Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote code execution. The vulnerability exi…
- CVE-2026-39527MEDIUMCVSS 5.4EG 5.42026-06-15
Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
- CVE-2026-39589CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
- CVE-2026-39591CRITICALCVSS 9.9EG 9.92026-06-15
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
- CVE-2026-39598HIGHCVSS 8.0EG 8.02026-06-17
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
- CVE-2026-40040HIGHCVSS 8.8EG 8.82026-04-13
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file types by bypassing ineffective extension filtering to the /uploadfile endpoint. Attackers can upload executable files …
- CVE-2026-40262HIGHCVSS 8.7EG 8.72026-04-17
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection for content type, which does not identify text-based formats such…
- CVE-2026-40412CRITICALCVSS 9.8EG 10.02026-05-26
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
- CVE-2026-40484CRITICALCVSS 9.1EG 9.12026-04-18
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document roo…
- CVE-2026-40487HIGHCVSS 8.9EG 8.92026-04-18
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type`…
- CVE-2026-40488HIGHCVSS 8.8EG 8.82026-04-20
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product cust…
- CVE-2026-40548MEDIUMCVSS 6.4EG 6.42026-06-01
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on …
- CVE-2026-40746CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
- CVE-2026-40747CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
- CVE-2026-40748CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- CVE-2026-40749CRITICALCVSS 9.9EG 9.92026-06-17
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- CVE-2026-40750CRITICALCVSS 9.9EG 9.92026-06-16
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
- CVE-2026-40772CRITICALCVSS 10.0EG 10.02026-06-15
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
- CVE-2026-41269HIGHCVSS 7.1EG 7.12026-04-23
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker u…
- CVE-2026-41517UnratedEG 0.02026-05-08
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor install…
- CVE-2026-41587HIGHCVSS 8.6EG 8.62026-05-07
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated…
- CVE-2026-4191HIGHCVSS 7.3EG 7.32026-03-16
A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be …
- CVE-2026-41937HIGHCVSS 7.2EG 7.22026-05-14
Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containin…
- CVE-2026-41938HIGHCVSS 8.8EG 8.82026-05-06
Vvveb before version 1.0.8.2 contains an unrestricted file upload vulnerability in the media upload handler that allows authenticated users with media-upload permissions to bypass extension restrictions by uploading a .htaccess file to map…
- CVE-2026-4201HIGHCVSS 7.3EG 7.32026-03-16
A weakness has been identified in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This vulnerability affects the function Upload of the file business/business-system/src/main/java/com/glowxq/system/admin/controller/SysFile…
- CVE-2026-42145LOWCVSS 3.1EG 3.12026-07-07
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not e…
- CVE-2026-4220HIGHCVSS 7.3EG 7.32026-03-16
A vulnerability has been found in Technologies Integrated Management Platform 7.17.0. Affected by this issue is some unknown functionality of the file /SetWebpagePic.jsp. The manipulation of the argument targetPath/Suffix leads to unrestri…
- CVE-2026-4221HIGHCVSS 7.3EG 7.32026-03-16
A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This affects an unknown part of the file /rest/file/uploadLedImage of the component Endpoint. The manipulation of the argument File results in unrestricted up…
- CVE-2026-42538MEDIUMCVSS 6.3EG 6.32026-06-04
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing …
- CVE-2026-42748CRITICALCVSS 9.9EG 9.92026-05-27
Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.
- CVE-2026-42844HIGHCVSS 8.8EG 8.82026-05-12
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created …
- CVE-2026-42879MEDIUMCVSS 6.3EG 6.32026-05-27
FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' product image upload functionality. An attacker with valid creden…
- CVE-2026-43752MEDIUMCVSS 4.9EG 4.92026-07-09
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMa…
- CVE-2026-44088HIGHCVSS 8.6EG 8.62026-05-15
SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Central Directory from the end). It can lea…
- CVE-2026-44566HIGHCVSS 7.3EG 7.32026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original HTTP upload request and is not validate…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →