CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,297)
page 206 of 215| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67206 | Hig | 0.00 | 8.8 | 0.00 | Jul 30, 2026 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the… | ||
| CVE-2026-44103 | Med | 0.00 | 5.3 | 0.00 | Jul 30, 2026 | An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected… | ||
| CVE-2026-44097 | Hig | 0.00 | 7.1 | 0.00 | Jul 30, 2026 | A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service. | ||
| CVE-2026-16610 | Cri | 0.00 | 9.8 | 0.01 | Jul 30, 2026 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no… | ||
| CVE-2026-14270 | Hig | 0.00 | 8.8 | 0.01 | Jul 29, 2026 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings()… | ||
| CVE-2026-63228 | Low | 0.00 | 2.6 | 0.00 | Jul 29, 2026 | An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server. | ||
| CVE-2026-63227 | Cri | 0.00 | 9.9 | 0.00 | Jul 29, 2026 | An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server. | ||
| CVE-2026-13714 | Cri | 0.00 | 9.8 | 0.00 | Jul 27, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically… | ||
| CVE-2026-10818 | Hig | 0.00 | 8.1 | 0.00 | Jul 25, 2026 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been… | ||
| CVE-2026-24727 | Cri | 0.00 | — | 0.01 | Jul 24, 2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted… | ||
| CVE-2026-65461 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | ||
| CVE-2026-65455 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-27064 | Cri | 0.00 | 9.1 | 0.00 | Jul 23, 2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | ||
| CVE-2026-14282 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the… | ||
| CVE-2026-63048 | Cri | 0.00 | — | 0.00 | Jul 22, 2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | ||
| CVE-2026-16451 | Med | 0.00 | 6.3 | 0.00 | Jul 21, 2026 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument… | ||
| CVE-2026-16447 | Hig | 0.00 | 7.3 | 0.01 | Jul 21, 2026 | A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has… | ||
| CVE-2026-16332 | Hig | 0.00 | 7.3 | 0.01 | Jul 21, 2026 | A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is… | ||
| CVE-2026-16331 | Hig | 0.00 | 7.3 | 0.01 | Jul 21, 2026 | A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has… | ||
| CVE-2026-16330 | Hig | 0.00 | 7.3 | 0.01 | Jul 21, 2026 | A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes… |
- risk 0.00cvss 8.8epss 0.00
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the…
- risk 0.00cvss 5.3epss 0.00
An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore service transmits firmware updates without performing integrity or verification check. Successful exploitation may compromise the integrity of the affected…
- risk 0.00cvss 7.1epss 0.00
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
- risk 0.00cvss 9.8epss 0.01
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no…
- risk 0.00cvss 8.8epss 0.01
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings()…
- risk 0.00cvss 2.6epss 0.00
An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registration endpoint, potentially enabling further attacks on the server.
- risk 0.00cvss 9.9epss 0.00
An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.
- risk 0.00cvss 9.8epss 0.00
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically…
- risk 0.00cvss 8.1epss 0.00
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been…
- risk 0.00cvss —epss 0.01
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted…
- risk 0.00cvss 9.1epss 0.00
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- risk 0.00cvss 9.1epss 0.00
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 9.1epss 0.00
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
- risk 0.00cvss 9.8epss 0.01
The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the…
- risk 0.00cvss —epss 0.00
Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.
- risk 0.00cvss 6.3epss 0.00
A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument…
- risk 0.00cvss 7.3epss 0.01
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has…
- risk 0.00cvss 7.3epss 0.01
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is…
- risk 0.00cvss 7.3epss 0.01
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has…
- risk 0.00cvss 7.3epss 0.01
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes…