CWE-434
Medium likelihoodUnrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
4,225 vulnerabilities with CWE-434
CVE-2026-15539
MEDIUM
SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload
CVSS 4.7
CVE-2026-15553
MEDIUM
Ragic|Enterprise Cloud Database - Arbitrary File Upload
CVSS 5.3
CVE-2026-15518
MEDIUM
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
CVSS 4.7
CVE-2026-15488
HIGH
hcr707305003 shiroiAdmin FileController.php upload unrestricted upload
CVSS 7.3
CVE-2026-61448
LOW
Parse Server 9.0.0 Stored XSS via malformed Content-Type
CVE-2026-57828
HIGH
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
CVSS 8.8
CVE-2026-57827
CRITICAL
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
CVSS 9.8
CVE-2026-2354
HIGH
Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
CVSS 8.8
CVE-2026-15282
CRITICAL
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.8
CVE-2026-14894
CRITICAL
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
CVSS 9.8
CVE-2026-13430
HIGH
Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
CVSS 7.2
CVE-2026-43752
MEDIUM
Claris FileMaker Server < 26.0.1 - Arbitrary Code Execution
CVSS 4.9
CVE-2026-56291
CRITICAL
KEV
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CVSS 9.8
CVE-2026-15158
CRITICAL
Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
CVSS 9.8
CVE-2026-55778
LOW
Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist
CVE-2026-58654
MEDIUM
Grav - Arbitrary File Upload via Avatar Endpoint
CVSS 4.3
CVE-2026-58480
CRITICAL
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
CVSS 9.8
CVE-2026-14489
HIGH
WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter
CVSS 8.8
CVE-2026-14158
HIGH
Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter
CVSS 8.8
CVE-2026-55633
HIGH
DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass
CVE-2026-23698
HIGH
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
CVSS 7.2
CVE-2026-23697
HIGH
Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module
CVSS 8.8
CVE-2026-14345
CRITICAL
WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter
CVSS 9.8
CVE-2026-42145
LOW
Coolify: File Upload Without Type or Size Validation in Database Backup Restore
CVSS 3.1
CVE-2026-9182
CRITICAL
ArcGIS Server 12.0 - Unrestricted File Upload
CVSS 9.8
Details
Vulnerabilities
4,225
Exploit Likelihood
Medium