CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,227 vulnerabilities with CWE-434
CVE-2026-1126 MEDIUM
LWJ Flow - Unrestricted File Upload in SVG File Handler
CVSS 6.3
CVE-2026-1107 MEDIUM
EyouCMS <1.7.1/5.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-1061 MEDIUM
xiweicheng TMS <2.28.0 - Unrestricted Upload
CVSS 6.3
CVE-2026-21625 HIGH
Stackideas Easydiscuss < 5.0.15 - Unrestricted File Upload
CVSS 8.8
CVE-2026-0496 MEDIUM
SAP Fiori App Intercompany Balance Reconciliation - File Upload
CVSS 6.6
CVE-2026-22799 HIGH
emlog < 2.6.1 - Authenticated Arbitrary File Upload via REST API Endpoint
CVSS 8.8
CVE-2026-22789 MEDIUM
Wem - Unrestricted File Upload
CVSS 5.4
CVE-2026-22786 HIGH
gin-vue-admin <= 2.8.7 - Path Traversal and Arbitrary File Write via Breakpoint Resume Upload
CVSS 7.2
CVE-2026-22783 CRITICAL
Iris <2.4.24 - Privilege Escalation
CVSS 9.6
CVE-2026-22241 HIGH
Openeclass < 4.1 - Unrestricted File Upload
CVSS 7.2
CVE-2026-21877 CRITICAL
n8n 0.123.0-1.121.2 - Authenticated Remote Code Execution via Git Node
CVSS 9.9
CVE-2026-0643 HIGH
projectworlds House Rental and Property Listing 1.0 - Unrestricted File Upload via Signup Image Parameter
CVSS 7.3
CVE-2026-0577 MEDIUM
Online Product Reservation System 1.0 - Unrestricted File Upload in prod.php
CVSS 6.3
CVE-2026-0566 MEDIUM
code-projects Content Management System 1.0 - Unrestricted File Upload via Image Argument
CVSS 4.7
CVE-2026-0547 MEDIUM
Online Course Registration < 3.1 - Unrestricted File Upload via Student Registration Page
CVSS 6.3
CVE-2025-24815 HIGH
Nokia MantaRay NM < 25R2-NM - Authenticated Unrestricted File Upload
CVSS 7.8
CVE-2025-69129 CRITICAL
WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site plugin <= 1.0.7 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2025-60218 CRITICAL
WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability
CVSS 9.9
CVE-2025-59872 MEDIUM
HCL ZIE for Web 16.0 - Unrestricted File Upload
CVSS 4.3
CVE-2025-40808 MEDIUM
Siemens Siprotec 5 6MD84 (CP300) - Unrestricted Upload of File with Dangerous Type
CVSS 6.1
CVE-2025-65416 MEDIUM
docuFORM Managed Print Service Client 11.11c - Arbitrary File Upload
CVSS 6.3
CVE-2025-67886 MEDIUM
Bitrix24 through 25.100.300 - Remote Code Execution
CVSS 6.3
CVE-2025-36074 MEDIUM
Security vulnerability has been detected in IBM Security Verify Directory
CVSS 5.5
CVE-2025-14938 MEDIUM
Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload
CVSS 5.3
CVE-2025-59710 HIGH
BizTalk360 <11.5 - Malicious DLL Remote Code Execution
CVSS 8.8
Details
Vulnerabilities 4,227
Exploit Likelihood Medium