CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,276 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 85 of 86
- CVE-2026-5576MEDIUMCVSS 4.7EG 4.72026-04-05
A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functionality of the file save_emp.php of the component Add Employee Page. This manipulation causes unrestricted upload. Remo…
- CVE-2026-55778LOWCVSS 2.1EG 2.12026-06-19
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.11 and 8.6.81, the default fileUpload.fileExtensions blocklist could be bypassed by uploading a file with a non-st…
- CVE-2026-56027CRITICALCVSS 9.9EG 9.92026-06-26
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
- CVE-2026-56058CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
- CVE-2026-56059CRITICALCVSS 9.9EG 9.92026-06-26
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
- CVE-2026-56290CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-29
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and l…
- CVE-2026-56291CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-09
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads…
- CVE-2026-56414HIGHCVSS 7.2EG 7.22026-06-26
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This de…
- CVE-2026-5670MEDIUMCVSS 6.3EG 6.32026-04-06
A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipula…
- CVE-2026-5704MEDIUMCVSS 5.0EG 5.02026-04-06
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, poten…
- CVE-2026-5718HIGHCVSS 8.1EG 8.12026-04-17
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.7. This is due to insufficient file type validation that occurs when custom black…
- CVE-2026-57311MEDIUMCVSS 5.3EG 5.32026-07-20
Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has on…
- CVE-2026-57658CRITICALCVSS 9.1EG 9.12026-06-26
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
- CVE-2026-57700CRITICALCVSS 10.0EG 10.02026-06-25
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
- CVE-2026-57710CRITICALCVSS 9.9EG 9.92026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.
- CVE-2026-57719CRITICALCVSS 10.0EG 10.02026-07-13
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
- CVE-2026-57827CRITICALCVSS 9.8EG 9.82026-07-11
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full …
- CVE-2026-57828HIGHCVSS 8.8EG 8.82026-07-11
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and…
- CVE-2026-58409CRITICALCVSS 9.1EG 9.12026-07-13
ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. The …
- CVE-2026-58480CRITICALCVSS 9.8EG 9.82026-07-08
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function ex…
- CVE-2026-58654MEDIUMCVSS 4.3EG 4.32026-07-08
The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType…
- CVE-2026-60032CRITICALCVSS 9.4EG 9.42026-07-20
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. poly…
- CVE-2026-61424CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-61448LOWCVSS 2.1EG 2.12026-07-11
Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-…
- CVE-2026-61457HIGHCVSS 8.8EG 8.82026-07-15
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PAT…
- CVE-2026-61900CRITICALCVSS 10.0EG 10.02026-07-20
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
- CVE-2026-6211HIGHCVSS 8.7EG 8.72026-06-12
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WEOLL: from 2.0.9 before 3.2.45.33.
- CVE-2026-6249HIGHCVSS 8.8EG 8.82026-04-20
Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated attackers to execute arbitrary operating system commands by uploading a PHP webshell with a .phtml extension. Attackers …
- CVE-2026-6257CRITICALCVSS 9.1EG 9.12026-04-20
Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file rename handler allows authenticated attackers to rename files to blocked extensions .php o…
- CVE-2026-6261HIGHCVSS 8.8EG 8.82026-05-05
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directo…
- CVE-2026-6271CRITICALCVSS 9.8EG 9.82026-05-14
The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. This is due to missing file type validation. This makes it possible for unauthenticated att…
- CVE-2026-63048CRITICALCVSS 9.4EG 9.42026-07-22
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
- CVE-2026-63429HIGHCVSS 8.6EG 8.62026-07-20
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous intern…
- CVE-2026-6489MEDIUMCVSS 6.3EG 6.32026-04-17
A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation …
- CVE-2026-6518HIGHCVSS 8.8EG 8.82026-04-18
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. …
- CVE-2026-65455CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- CVE-2026-65461CRITICALCVSS 9.1EG 9.12026-07-23
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- CVE-2026-6555CRITICALCVSS 9.8EG 9.82026-05-20
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension an…
- CVE-2026-6561MEDIUMCVSS 4.7EG 4.72026-04-19
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The …
- CVE-2026-6596HIGHCVSS 7.3EG 7.32026-04-20
A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results i…
- CVE-2026-6602HIGHCVSS 7.3EG 7.32026-04-20
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic resul…
- CVE-2026-6650MEDIUMCVSS 4.7EG 4.72026-04-20
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may…
- CVE-2026-6692HIGHCVSS 8.8EG 8.82026-05-07
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due to insufficient file type validation. This makes it possibl…
- CVE-2026-6835MEDIUMCVSS 6.1EG 6.12026-04-22
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result in a XSS-like effect.
- CVE-2026-6885CRITICALCVSS 9.8EG 9.82026-04-23
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code e…
- CVE-2026-6933HIGHCVSS 8.8EG 8.82026-06-16
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before p…
- CVE-2026-6960CRITICALCVSS 9.8EG 9.82026-05-21
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes…
- CVE-2026-7043MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The ex…
- CVE-2026-7044MEDIUMCVSS 6.3EG 6.32026-04-26
A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has be…
- CVE-2026-7107MEDIUMCVSS 6.3EG 6.32026-04-27
A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to b…
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →