← Back
CWE-434

4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wdmtech
1Vbizz
Aug 17, 2026
Jun 19, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attacker...Show more
Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution.Show less
-
-
Aug 10, 2026
Jun 19, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename...Show more
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %).Show less
-
-
Jun 18, 2026
Jun 18, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insuffic...Show more
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() does not strip single quotes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing — allowing a single quote in the account-id or api-key parameter to break out of the single-quoted PHP string literal in the write_config() define() statement. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. This is possible because the 'cf-images-nonce' nonce required by the AJAX handler is exposed to all Author-level and above users on wp-admin/upload.php via the CFImages JavaScript object, meaning any upload-capable user can satisfy the nonce check and reach the vulnerable wp-config.php write path.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
1Hcltech
1Zie For Web
Jun 26, 2026
Jun 17, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web...Show more
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the codeShow less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
-
-
Jun 17, 2026
Jun 16, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
-
-
Jun 17, 2026
Jun 16, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authoriza...Show more
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with the 'createFromStub' function performing unsanitized string substitution of the 'premmerce_plugin_namespace' parameter directly into PHP stub files written to the wp-content/plugins/ directory. An attacker can inject a semicolon followed by arbitrary PHP code into the namespace parameter, causing the generated plugin file to contain and execute that code when accessed via HTTP. This makes it possible for authenticated attackers with Subscriber-level access and above to create arbitrary PHP files on the server and achieve remote code execution.Show less
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.