CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,225 vulnerabilities with CWE-434
CVE-2026-15539 MEDIUM
SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
CVSS 4.7
CVE-2026-15553 MEDIUM
Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVSS 5.3
CVE-2026-15518 MEDIUM
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
CVSS 4.7
CVE-2026-15488 HIGH
hcr707305003 shiroiAdmin FileController.php upload unrestricted upload
CVSS 7.3
CVE-2026-61448 LOW
Parse Server 9.0.0 Stored XSS via malformed Content-Type
CVE-2026-57828 HIGH
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
CVSS 8.8
CVE-2026-57827 CRITICAL
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
CVSS 9.8
CVE-2026-2354 HIGH
Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
CVSS 8.8
CVE-2026-15282 CRITICAL
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.8
CVE-2026-14894 CRITICAL
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
CVSS 9.8
CVE-2026-13430 HIGH
Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
CVSS 7.2
CVE-2026-43752 MEDIUM
Claris FileMaker Server < 26.0.1 - Arbitrary Code Execution
CVSS 4.9
CVE-2026-56291 CRITICAL KEV
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CVSS 9.8
CVE-2026-15158 CRITICAL
Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
CVSS 9.8
CVE-2026-55778 LOW
Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
CVE-2026-58654 MEDIUM
Grav - Arbitrary File Upload via Avatar Endpoint
CVSS 4.3
CVE-2026-58480 CRITICAL
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
CVSS 9.8
CVE-2026-14489 HIGH
WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
CVSS 8.8
CVE-2026-14158 HIGH
Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
CVSS 8.8
CVE-2026-55633 HIGH
DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
CVE-2026-23698 HIGH
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
CVSS 7.2
CVE-2026-23697 HIGH
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
CVSS 8.8
CVE-2026-14345 CRITICAL
WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter
CVSS 9.8
CVE-2026-42145 LOW
Coolify: File Upload Without Type or Size Validation in Database Backup Restore
CVSS 3.1
CVE-2026-9182 CRITICAL
ArcGIS Server 12.0 - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities 4,225
Exploit Likelihood Medium