CWE-434: Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
2,406 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-56291 — Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
- CVE-2026-56290 — Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
- CVE-2026-48939 — Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
- CVE-2026-48908 — Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2
- CVE-2025-34077 — WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
- CVE-2025-31324 — Missing Authorization check in SAP NetWeaver (Visual Composer development server)
- CVE-2024-57968 — Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones
- CVE-2025-34299 — Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
- CVE-2024-27115 — Remote Code Execution through File Upload in SOPlanning before 1.52.02
- CVE-2025-34111 — Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
- CVE-2024-9932 — Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
- CVE-2025-34511 — Sitecore PowerShell Extension RCE via Unrestricted Upload
- CVE-2025-34100 — BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
- CVE-2024-9290 — Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload
- CVE-2024-49668 — WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
- CVE-2024-49653 — WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
- CVE-2024-51793 — WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
- CVE-2025-34040 — Seeyon Zhiyuan OA System Path Traversal File Upload
- CVE-2025-34086 — Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
- CVE-2025-68109 — ChurchCRM vulnerable to RCE with database restore functionality
Recently published
- CVE-2026-26212 — Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE
- CVE-2026-54611 — InstantCMS has Remote Code Execution in package installer
- CVE-2026-86666 — aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload
- CVE-2026-50093 — A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control P
- CVE-2026-86305 — light0011 cms Upload.class.php upload unrestricted upload
- CVE-2026-86272 — Beijing Meite Software Technology U+Smart Enjoyment WebSite UploadFormImg.ashx unrestricted upload
- CVE-2026-86239 — liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload
- CVE-2026-44402 — Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
- CVE-2026-12483 — LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler
- CVE-2026-85208 — itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload
- CVE-2026-85186 — itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload
- CVE-2026-85135 — ILIAS MediaPool ZipAdapter.php uploadMultipleSubtitleFileObject unrestricted upload
- CVE-2026-76174 — Multiple vulnerabilities in Ocsreports for OCS Inventory NG
- CVE-2026-82524 — UnoPim File Upload RCE via TinyMCE Image Upload Endpoint
- CVE-2026-53649 — Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
- CVE-2026-19219 — DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
- CVE-2026-19513 — Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion
- CVE-2026-84147 — Remote Code Execution Vulnerability in Manacle Technologies ERP System
- CVE-2026-75865 — WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
- CVE-2026-82921 — ShopEx ECShop pack.php check_img_type unrestricted upload