CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,314)
page 18 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67688 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code. | ||
| CVE-2026-12872 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2026 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible… | ||
| CVE-2026-21662 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2026 | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. | ||
| CVE-2026-14483 | Cri | 0.64 | 9.8 | 0.02 | Jul 31, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly… | ||
| CVE-2026-40749 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. | ||
| CVE-2026-40748 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | ||
| CVE-2026-40747 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. | ||
| CVE-2026-40746 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | ||
| CVE-2026-39589 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. | ||
| CVE-2026-27041 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | ||
| CVE-2026-25446 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | ||
| CVE-2026-22327 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. | ||
| CVE-2025-60218 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. | ||
| CVE-2024-52488 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions. | ||
| CVE-2026-40750 | Cri | 0.64 | 9.9 | 0.00 | Jun 16, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9. | ||
| CVE-2026-39591 | Cri | 0.64 | 9.9 | 0.00 | Jun 15, 2026 | Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions. | ||
| CVE-2026-50873 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file. | ||
| CVE-2018-25436 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2026 | WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file… | ||
| CVE-2026-53787 | Cri | 0.64 | 9.8 | 0.05 | Jun 12, 2026 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint… | ||
| CVE-2026-11839 | Cri | 0.64 | 9.9 | 0.00 | Jun 11, 2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003. |
- risk 0.64cvss 9.8epss 0.01
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible…
- risk 0.64cvss 9.8epss 0.01
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
- risk 0.64cvss 9.8epss 0.02
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly…
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
- risk 0.64cvss 9.9epss 0.00
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
- risk 0.64cvss 9.9epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
- risk 0.64cvss 9.8epss 0.00
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
- risk 0.64cvss 9.8epss 0.01
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file…
- risk 0.64cvss 9.8epss 0.05
Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint…
- risk 0.64cvss 9.9epss 0.00
Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.