CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,225 vulnerabilities with CWE-434
CVE-2026-10071 CRITICAL
Interinfo|DreamMaker - Arbitrary File Upload
CVSS 9.8
CVE-2026-30761 HIGH
SourceBans Material Admin 1.1.6 - Arbitrary File Upload and Remote Code Execution via Admin Upload Map Image
CVSS 7.3
CVE-2026-9227 HIGH
GutenBee <= 2.20.1 - Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter
CVSS 8.8
CVE-2026-9009 HIGH
Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute
CVSS 8.8
CVE-2026-42879 MEDIUM
FacturaScripts: Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
CVSS 6.3
CVE-2026-46426 HIGH
Budibase: Unrestricted Upload of File with Dangerous Type
CVSS 7.6
CVE-2026-45089 HIGH
Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server Mode
CVSS 8.2
CVE-2026-42748 CRITICAL
WordPress WPify Woo Czech plugin <= 5.4.1 - Arbitrary File Upload vulnerability
CVSS 9.9
CVE-2026-9445 MEDIUM
SourceCodester Simple POS and Inventory System File Extension addproduct.php unrestricted upload
CVSS 6.3
CVE-2026-9421 HIGH
KLiK SocialMediaWebsite File upload.inc.php uniqid unrestricted upload
CVSS 7.3
CVE-2026-9374 MEDIUM
yangzongzhuan RuoYi-Vue Common Upload Endpoint upload FileUploadUtils.upload unrestricted upload
CVSS 6.3
CVE-2026-40412 CRITICAL
Azure Orbital Spatio Remote Code Execution Vulnerability
CVSS 10.0
CVE-2026-9053 MEDIUM
9front - Arbitrary File Overwrite via HTML File Upload Form Default Path
CVE-2026-6960 CRITICAL
BookingPress Pro <= 5.6 - Unauthenticated Arbitrary File Upload via Signature Custom Field
CVSS 9.8
CVE-2026-8134 HIGH
Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
CVSS 7.2
CVE-2026-9157 HIGH
Remote Code Execution in Gmission Web FAX
CVSS 8.4
CVE-2026-9102 CRITICAL
Path Traversal in Altium Enterprise Server ComparisonService Allows Arbitrary File Write
CVE-2026-45444 CRITICAL
WordPress Gift Cards For WooCommerce Pro plugin <= 4.2.6 - Arbitrary File Upload vulnerability
CVSS 10.0
CVE-2026-6555 CRITICAL
ProSolution WP Client <= 2.0.0 - Unauthenticated Arbitrary File Upload via 'files'
CVSS 9.8
CVE-2026-4883 CRITICAL
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
CVSS 9.8
CVE-2026-4885 CRITICAL
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
CVSS 9.8
CVE-2026-27891 HIGH
Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism
CVSS 7.2
CVE-2026-8758 HIGH
Metasoft 美特软件 MetaCRM upload3.jsp unrestricted upload
CVSS 7.3
CVE-2026-45315 HIGH
Open WebUI: Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
CVSS 8.7
CVE-2026-44566 HIGH
Open WebUI: Arbitrary File Upload and Path Traversal
CVSS 7.3
Details
Vulnerabilities 4,225
Exploit Likelihood Medium