CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,223 vulnerabilities with CWE-434
CVE-2026-63223 CRITICAL
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
CVSS 9.8
CVE-2026-67206 HIGH
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
CVSS 8.8
CVE-2026-44103 MEDIUM
JupiCore does not perform validation of firmware
CVSS 5.3
CVE-2026-44097 HIGH
Phoenix Contact CHARX SEC < 1.9.1 - Arbitrary File Upload
CVSS 7.1
CVE-2026-16610 CRITICAL
WordPress ASE Pro <= 8.9.0 - Unauthenticated PHP Code Injection
CVSS 9.8
CVE-2026-65885 CRITICAL
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2
CVE-2026-14270 HIGH
Extra Checkout Options < 2.3.2 - Remote Code Execution
CVSS 8.8
CVE-2026-63228 LOW
Three Learning Koollab LMS - Unrestricted Image Upload Vulnerability
CVSS 2.6
CVE-2026-63227 CRITICAL
Unrestricted SCORM file upload vulnerability
CVSS 9.9
CVE-2026-12476 HIGH
Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter
CVSS 7.2
CVE-2026-13714 CRITICAL
Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
CVSS 9.8
CVE-2026-10818 HIGH
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
CVSS 8.1
CVE-2026-24727 CRITICAL
SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type
CVE-2026-65461 CRITICAL
WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-65455 CRITICAL
WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-27064 CRITICAL
WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-14282 CRITICAL
GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field
CVSS 9.8
CVE-2026-63048 CRITICAL
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2
CVE-2026-16451 MEDIUM
zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload
CVSS 6.3
CVE-2026-16447 HIGH
D-Link DNS-320 multi_uploadify.php unrestricted upload
CVSS 7.3
CVE-2026-16332 HIGH
D-Link DNS-320 multi_uploadify.php unrestricted upload
CVSS 7.3
CVE-2026-16331 HIGH
D-Link DNS-320 save_ajax.php unrestricted upload
CVSS 7.3
CVE-2026-16330 HIGH
D-Link DNS-320 uploadify.php unrestricted upload
CVSS 7.3
CVE-2026-16329 HIGH
D-Link DNS-320 uploadify.php unrestricted upload
CVSS 7.3
CVE-2026-16327 HIGH
D-Link DNS-320 upload.php unrestricted upload
CVSS 7.3
Details
Vulnerabilities 4,223
Exploit Likelihood Medium