CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 19 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15748 | Cri | 0.64 | 9.8 | 0.05 | Aug 18, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist… | ||
| CVE-2026-67678 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | ||
| CVE-2026-16098 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which… | ||
| CVE-2026-18391 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2026 | The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a… | ||
| CVE-2026-15039 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2026 | The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution. | ||
| CVE-2026-72592 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2026 | An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no authentication enabled by default… | ||
| CVE-2026-19089 | Cri | 0.64 | 9.8 | 0.00 | Aug 10, 2026 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files… | ||
| CVE-2022-4995 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2026 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js… | ||
| CVE-2026-70558 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard… | ||
| CVE-2026-67688 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2026 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code. | ||
| CVE-2026-14175 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2026 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1. | ||
| CVE-2026-16618 | Cri | 0.64 | 9.8 | 0.00 | Aug 4, 2026 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable… | ||
| CVE-2026-16250 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2026 | The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution. | ||
| CVE-2026-16060 | Cri | 0.64 | 9.8 | 0.00 | Aug 3, 2026 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in… | ||
| CVE-2026-12872 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2026 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible… | ||
| CVE-2026-21662 | Cri | 0.64 | 9.8 | 0.00 | Jul 31, 2026 | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1. | ||
| CVE-2026-14483 | Cri | 0.64 | 9.8 | 0.04 | Jul 31, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly… | ||
| CVE-2026-40749 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. | ||
| CVE-2026-40748 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. | ||
| CVE-2026-40747 | Cri | 0.64 | 9.9 | 0.00 | Jun 17, 2026 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. |
- risk 0.64cvss 9.8epss 0.05
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist…
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
- risk 0.64cvss 9.8epss 0.01
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which…
- risk 0.64cvss 9.8epss 0.01
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a…
- risk 0.64cvss 9.8epss 0.01
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.
- risk 0.64cvss 9.8epss 0.01
An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no authentication enabled by default…
- risk 0.64cvss 9.8epss 0.00
The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files…
- risk 0.64cvss 9.8epss 0.01
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js…
- risk 0.64cvss 9.8epss 0.01
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard…
- risk 0.64cvss 9.8epss 0.01
ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.00
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
- risk 0.64cvss 9.8epss 0.00
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable…
- risk 0.64cvss 9.8epss 0.01
The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.00
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in…
- risk 0.64cvss 9.8epss 0.01
The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible…
- risk 0.64cvss 9.8epss 0.00
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
- risk 0.64cvss 9.8epss 0.04
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly…
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
- risk 0.64cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.