← Back
CWE-434

4,378 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,378)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Mobile Security
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the...Show more
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32525.Show less
1Trendmicro
1Mobile Security
Jun 17, 2026
Jun 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the...Show more
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32526.Show less
1Blogengine
1Blogengine.net
Jun 17, 2026
Jun 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
1Bludit
1Bludit
Jun 17, 2026
Jun 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
1Mgt Commerce
1Cloudpanel
Jun 17, 2026
Jun 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
1Yoga Class Registration System Project
1Yoga Class Registration System
Jun 17, 2026
Jun 24, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the adm...Show more
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators. Show less
1Pluck Cms
1Pluck
Jun 17, 2026
Jun 22, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue discovered in /admin.php in Pluck CMS 4.7.15 through 4.7.16-dev5 allows remote attackers to run arbitrary code via manage file functionality.
1Funadmin
1Funadmin
Jun 17, 2026
Jun 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
1Feehi
1Feehicms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
1Nucleuscms
1Nucleuscms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Jun 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.
1Feehi
1Feehicms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
1Pluck Cms
1Pluck
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
1Pluck Cms
1Pluck
Jun 17, 2026
Jun 20, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
18cms
1Ljcms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
1Pluck Cms
1Pluckcms
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
1Ebcms
1Ebcms
Jun 17, 2026
Jun 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
File upload vulnerability in ebCMS v.1.1.0 allows a remote attacker to execute arbitrary code via the upload type parameter.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Jun 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be in...Show more
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user privileges can be used to exploit this vulnerability. Editions other than Enterprise are also affected.Show less
1Unlimited Elements
1Unlimited Elements For Elementor
Jun 17, 2026
Jun 17, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up t...Show more
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.Show less
1Jeecg
1Jeecg Boot
Jun 17, 2026
Jun 16, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.