CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,225 vulnerabilities with CWE-434
CVE-2026-53948 MEDIUM
Ghost: File Upload Content-Type Spoofing
CVSS 5.4
CVE-2026-48939 CRITICAL KEV
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
CVSS 9.8
CVE-2026-48908 CRITICAL KEV
Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12
CVSS 9.8
CVE-2026-54414 CRITICAL
FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover
CVSS 9.8
CVE-2026-9860 HIGH
Offload, AI & Optimize With Cloudflare Images < 1.10.2 - Remote Code Execution
CVSS 8.8
CVE-2026-52705 CRITICAL
WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary File Upload vulnerability
CVSS 9.0
CVE-2026-40749 CRITICAL
WordPress Charity Zone theme <= 1.1.1 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-40748 CRITICAL
WordPress Kids Gift Shop theme <= 0.5.4 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-40747 CRITICAL
WordPress Ecommerce Zone theme <= 0.9.7 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-40746 CRITICAL
WordPress Restaurant Zone theme <= 0.7.8 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-39598 HIGH
WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability
CVSS 8.0
CVE-2026-39589 CRITICAL
WordPress Webenvo theme <= 0.0.6 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-27041 CRITICAL
WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-25446 CRITICAL
WordPress WishList Member X plugin <= 3.29.0 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-22327 CRITICAL
WordPress Restaurt theme <= 1.0.4 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-40750 CRITICAL
WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-6933 HIGH
Premmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation
CVSS 8.8
CVE-2026-40772 CRITICAL
WordPress GeekyBot plugin <= 1.2.2 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2026-39591 CRITICAL
WordPress WP-BusinessDirectory plugin <= 4.0.0 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-39527 MEDIUM
WordPress WpStream plugin < 4.11.2 - Arbitrary File Upload vulnerability
CVSS 5.4
CVE-2026-50873 CRITICAL
flatnotes 5.5.4 - Arbitrary File Upload and Remote Code Execution via Attachment Handling
CVSS 9.8
CVE-2026-5482 CRITICAL
Remote Code Execution via Unrestricted File Upload in Responsive FileManager
CVE-2026-34027 MEDIUM
Wertheim SafeController 6.15.8328.28014 - Authenticated Arbitrary File Upload
CVE-2026-53724 LOW
Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
CVE-2026-6211 HIGH
Arbitrary File Upload in Global IT's WEOLL
CVSS 8.7
Details
Vulnerabilities 4,225
Exploit Likelihood Medium