CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,223 vulnerabilities with CWE-434
CVE-2026-16324 HIGH
Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload
CVSS 7.3
CVE-2026-53593 HIGH
FreeScout < 1.8.224 - Authenticated Remote Code Execution via .pht Upload
CVSS 8.8
CVE-2026-61900 CRITICAL
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CVE-2026-61424 CRITICAL
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
CVE-2026-60032 CRITICAL
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0
CVE-2026-63429 HIGH
HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context
CVSS 8.6
CVE-2026-45797 MEDIUM
HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload
CVE-2026-57311 MEDIUM
Unrestricted Upload of File with Dangerous Type in Windu CMS
CVE-2026-16226 MEDIUM
SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings unrestricted upload
CVSS 4.7
CVE-2026-48062 CRITICAL
CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule
CVSS 9.8
CVE-2026-36669 CRITICAL
Feng Office 3.11.13.11 - Unauthenticated Arbitrary File Upload via ck_upload_handler.php
CVSS 9.8
CVE-2026-13352 HIGH
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content < 4.16.18 - Remote Code Execution
CVSS 8.8
CVE-2026-12684 MEDIUM
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
CVSS 6.5
CVE-2026-50124 HIGH
DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper
CVE-2026-61457 HIGH
Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass
CVSS 8.8
CVE-2026-11579 MEDIUM
Kali Forms < 2.4.17 - Unauthenticated Media Upload
CVSS 5.3
CVE-2026-48356 CRITICAL
Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVSS 9.3
CVE-2026-15677 HIGH
code-projects Online Job Portal JobSeekerInsert.php unrestricted upload
CVSS 7.3
CVE-2026-58409 CRITICAL
ChurchCRM: Authenticated Remote Code Execution (RCE) via Malicious Plugin Upload
CVSS 9.1
CVE-2026-49972 HIGH
Laravel-Mediable < 7.0.0 File Upload RCE via Extension Bypass
CVSS 8.8
CVE-2026-14906 MEDIUM
Firefox for iOS < 152.4 - Saved PDF Resource Overwrite
CVSS 5.3
CVE-2026-57719 CRITICAL
WordPress Aimogen Pro plugin <= 2.8.3 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2026-57710 CRITICAL
WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-15539 MEDIUM
SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
CVSS 4.7
CVE-2026-15553 MEDIUM
Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVSS 5.3
Details
Vulnerabilities 4,223
Exploit Likelihood Medium