CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,226 vulnerabilities with CWE-434
CVE-2026-32989
HIGH
Precurio Intranet Portal 4.4: Cross-Site Request Forgery leading to arbitrary file upload
CVSS 8.8
CVE-2026-33071
MEDIUM
FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads
CVSS 4.3
CVE-2026-32985
CRITICAL
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution
CVSS 9.8
CVE-2026-32756
HIGH
Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Module
CVSS 8.8
CVE-2026-29104
LOW
SuiteCRM Vulnerable to Authenticated Arbitrary File Upload via Configurator addfontresult View in SuiteCRM
CVSS 2.7
CVE-2026-27043
HIGH
WordPress Photography theme <= 7.7.5 - Arbitrary File Upload vulnerability
CVSS 7.2
CVE-2026-27067
CRITICAL
WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-27540
CRITICAL
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability
CVSS 9.0
CVE-2026-29859
CRITICAL
aaPanel v7.57.0 - Arbitrary File Upload
CVSS 9.8
CVE-2026-28674
HIGH
xiaoheiFS Vulnerable to RCE via Arbitrary Payment Plugin Upload (Automatic Execution)
CVSS 7.2
CVE-2026-28673
HIGH
xiaoheiFS Vulnerable to RCE via Unrestricted Plugin Installation (Manifest Manipulation)
CVSS 7.2
CVE-2026-4221
HIGH
Tiandy Easy7 Integrated Management Platform Endpoint uploadLedImage unrestricted upload
CVSS 7.3
CVE-2026-4220
HIGH
Technologies Integrated Management Platform SetWebpagePic.jsp unrestricted upload
CVSS 7.3
CVE-2026-4201
HIGH
glowxq glowxq-oj SysFileController.java upload unrestricted upload
CVSS 7.3
CVE-2026-4191
HIGH
node-api-postgres up to 2.5 - Unrestricted Upload
CVSS 7.3
CVE-2026-3891
CRITICAL
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
CVSS 9.8
CVE-2026-3800
MEDIUM
janobe Resort Reservation System 1.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-3797
MEDIUM
Tiandy Video Surveillance System 7.17.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-3749
MEDIUM
Bytedesk <=1.3.9 - Unrestricted Upload
CVSS 6.3
CVE-2026-3748
MEDIUM
Bytedesk <=1.3.9 - Unrestricted Upload
CVSS 6.3
CVE-2026-29186
HIGH
Backstage plugin-techdocs-node < 1.14.3 - Arbitrary Code Execution via MkDocs Configuration Bypass
CVSS 7.7
CVE-2026-30821
CRITICAL
Flowise < 3.0.13 - Unauthenticated Unrestricted Upload of File with Dangerous Type via Spoofed Content-Type
CVSS 9.8
CVE-2026-28800
MEDIUM
Natro Macro <1.1.0 - Unauthenticated RCE
CVSS 6.4
CVE-2026-27605
MEDIUM
Chartbrew < 4.8.4 - Unauthenticated Arbitrary File Upload and Stored Cross-Site Scripting via Project Logo Upload
CVSS 6.3
CVE-2026-29041
HIGH
Chamilo <1.11.34 - Authenticated RCE
CVSS 8.8
Details
Vulnerabilities
4,226
Exploit Likelihood
Medium