CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,225 vulnerabilities with CWE-434
CVE-2026-24014 CRITICAL
Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
CVSS 9.8
CVE-2026-14777 MEDIUM
SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload
CVSS 6.3
CVE-2026-14776 MEDIUM
SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload
CVSS 6.3
CVE-2026-14775 MEDIUM
SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload
CVSS 6.3
CVE-2026-14736 HIGH
Ruijie RG-UAC user_auth_commit.php unrestricted upload
CVSS 7.3
CVE-2026-14698 MEDIUM
SourceCodester Syllabus-Aligned Learning Management and Examination System upload_files.php unrestricted upload
CVSS 6.3
CVE-2026-5524 CRITICAL
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
CVSS 9.8
CVE-2026-27419 CRITICAL
WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-53909 MEDIUM
MyComplianceOffice MCO 25.3.3.1 - Authenticated Arbitrary File Upload
CVSS 6.5
CVE-2026-48283 CRITICAL
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVSS 10.0
CVE-2026-48276 CRITICAL
ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)
CVSS 10.0
CVE-2026-53691 HIGH
Remote Code Execution in Redeight CMS
CVE-2026-56290 CRITICAL KEV
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
CVSS 9.8
CVE-2026-13165 HIGH
Remote Code Execution in SzafirHost
CVE-2026-13553 HIGH
itsourcecode Online Hotel Management System controller.php add unrestricted upload
CVSS 7.3
CVE-2026-13547 HIGH
Hanwang e-Face General Management Platform upload.do unrestricted upload
CVSS 7.3
CVE-2026-56414 HIGH
H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type
CVSS 7.2
CVE-2026-33560 HIGH
Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type
CVSS 7.1
CVE-2026-57658 CRITICAL
WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability
CVSS 9.1
CVE-2026-56059 CRITICAL
WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-56058 CRITICAL
WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-56027 CRITICAL
WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-57700 CRITICAL
WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2026-48946 MEDIUM
K2 for Joomla < 2.26 - Attachment PHP Upload Remote Code Execution
CVSS 6.3
CVE-2026-48945 MEDIUM
K2 for Joomla < 2.26 - Gallery Archive PHP Upload Remote Code Execution
CVSS 5.3
Details
Vulnerabilities 4,225
Exploit Likelihood Medium