← Back
CWE-434

4,376 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,376)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pyload
1Pyload
Jun 17, 2026
Apr 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix...Show more
pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.Show less
1Themeisle
1Product Addons & Fields For Woocommerce
Jun 17, 2026
Apr 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18....Show more
The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Successful exploitation requires the PPOM Pro plugin to be installed along with a WooCommerce product that contains a file upload field to retrieve the correct nonce.Show less
-
-
Jun 17, 2026
Apr 25, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
1Code Projects
1Simple School Management System
Jun 17, 2026
Apr 25, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.
1Thinkcmf
1Thinkcmf
Jun 17, 2026
Apr 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
1Redhat
1Trusted Profile Analyzer
Jun 17, 2026
Apr 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the...Show more
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.Show less
1Unlimited Elements
1Unlimited Elements For Elementor
Jun 17, 2026
Apr 24, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimite...Show more
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.Show less
-
-
Jun 17, 2026
Apr 24, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
-
-
Jun 17, 2026
Apr 24, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.5.11.
1Incsub
1Forminator
Jun 17, 2026
Apr 23, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the serve...Show more
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition. Show less
1Mozilo
1Mozilocms
Jun 17, 2026
Apr 22, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of m...Show more
An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extension restrictions via file renaming, potentially leading to unauthorized file execution or storage of malicious content.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Apr 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
1Ivanti
1Avalanche
Jun 17, 2026
Apr 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
1Library System Project
1Library System
Jun 17, 2026
Apr 18, 2024
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file \admin\student.add.php of the component Photo Han...Show more
A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file \admin\student.add.php of the component Photo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261440.Show less
1Jizhicms
1Jizhicms
Jul 9, 2026
Apr 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
jizhiCMS 2.5 suffers from a File upload vulnerability.
1Infotheme
1Wp Poll Maker
Jun 17, 2026
Apr 17, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.
-
-
Jun 17, 2026
Apr 17, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a local attacker to execute arbitrary code via the my_parser.php component.
1Phpgurukul
1Tourism Management System
Jun 17, 2026
Apr 16, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are...Show more
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.Show less
1Phpgurukul
1Tourism Management System
Jun 17, 2026
Apr 16, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are upl...Show more
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.Show less
1Mozilla
2Firefox
Thunderbird
Jun 17, 2026
Apr 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125...Show more
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.Show less