← Back
CWE-434

4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Coldfusion
Aug 28, 2026
Jun 30, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat...Show more
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.Show less
1Adobe
1Coldfusion
Aug 28, 2026
Jun 30, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat...Show more
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.Show less
-
-
Jun 30, 2026
Jun 30, 2026
8.6 HIGH· v4
N/A· v3
N/A· v2
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fa...Show more
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/admin/index.php?module=pages&mode=FileAdd" endpoint. The application fails to validate file extensions and MIME types, permitting the upload of arbitrary PHP scripts to the publicly accessible "/uploads/files/" directory where they can be executed directly by the web server.Show less
1Nokia
1Mantaray Nm
Jul 10, 2026
Jun 30, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.
1Joomlack
1Page Builder Ck
Jul 8, 2026
Jun 29, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
-
-
Jun 29, 2026
Jun 29, 2026
8.6 HIGH· v4
N/A· v3
N/A· v2
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). A...Show more
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a malicious DLL/SO/DYLIB as a local-file-header entry between the last legitimate entry and the Central Directory, without adding it to the Central Directory. The signature verifier never sees the injected entry and accepts the archive as validly signed; the extractor reads it sequentially and writes the attacker library to the native temp directory with no hash check), while the archive-size check still passes. This can lead to remote code execution. This issue was fixed in version 1.2.2.Show less
-
-
Jun 29, 2026
Jun 29, 2026
5.5 MEDIUM· v4
7.3 HIGH· v3
7.5 HIGH· v2
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lea...Show more
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been published and may be used.Show less
-
-
Jun 29, 2026
Jun 29, 2026
5.5 MEDIUM· v4
7.3 HIGH· v3
7.5 HIGH· v2
A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File...Show more
A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.Show less
-
-
Jun 29, 2026
Jun 26, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structur...Show more
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structure, or size. This design omission enables the placement of unexpected or malformed data in locations intended for trusted certificate material, which could affect system integrity or behavior even after reboot.Show less
1Daktronics
3Dmp 5000 Firmware
Dmp 8000 FirmwareVfc Dmp 5000 Firmware
Jul 6, 2026
Jun 26, 2026
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filterin...Show more
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filtering or content inspection is enforced which allows executable binaries and scripts to be accepted and written directly to the server.Show less
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
-
-
Jun 29, 2026
Jun 25, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
1Joomlaworks
1K2
Jun 28, 2026
Jun 25, 2026
N/A· v4
6.3 MEDIUM· v3
N/A· v2
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then f...Show more
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute arbitrary PHP code in the web server's context.Show less
1Joomlaworks
1K2
Jun 28, 2026
Jun 25, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are ext...Show more
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access.Show less
-
-
Jun 25, 2026
Jun 24, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the s...Show more
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. This vulnerability is fixed in 6.21.1.Show less
1Joomlic
1Icagenda
Jul 11, 2026
Jun 20, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
1Ollyo
1Sp Page Builder
Jul 8, 2026
Jun 20, 2026
10.0 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.