VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

186 CVEsRSS

CVE-2026-36467High· 7.2
today

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

Twilightvia NVD
CVE-2026-94383High· 8.6
today

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A …

TwilightMISP · MISPvia NVD
CVE-2026-82187Critical· 9.8
today

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to…

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to…

MidnightEPSS 0.14%via NVD
CVE-2026-88857Critical· 9.4
yesterday

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions saveWatermark() copied an uploaded file into a web-accessible directory using the …

MidnightOrdaSoft.com · com_osgallery_lightEPSS 0.47%via NVD
CVE-2026-94104High· 8.8
yesterday

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or when chunks parameter is 2 or higher. Attackers with view-only back-o…

Twilightnivocart · nivocartEPSS 0.67%via NVD
CVE-2026-81650High· 7.2
yesterday

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always pa…

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always pa…

TwilightEPSS 0.28%via NVD
CVE-2026-84750Medium· 6.5
2d ago

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension …

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its form fields, and stores them at a predictable public path with the attacker-chosen extension …

SunlitEPSS 0.27%via NVD
CVE-2026-84434Critical· 9.8PoC
2d ago

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persis…

AbyssalGravity Forms · Gravity FormsEPSS 0.70%via NVD
CVE-2026-93031High· 8.8
3d ago

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads functi…

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, and including, 3.8.3 via the download_file_to_uploads functi…

TwilightWP Cloud Plugins/_deleeuw_ · Use-your-Drive | Google Drive plugin for WordPressEPSS 0.58%via NVD
CVE-2026-77929High· 8.8
3d ago

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload:…

TwilightMacWarrior · clipbucket-v5EPSS 0.51%via NVD
CVE-2026-56590Medium· 6.4
3d ago

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to upload and execute malicious payloads, resulting in a compl…

SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.17%via NVD
CVE-2026-45140Critical· 9.8PoC
4d ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

Abyssalchamilo · chamilo-lmsEPSS 0.98%via NVD
CVE-2026-92980High· 7.2
4d ago

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can …

Twilightdanielbrendel · hortusfox-webEPSS 0.53%via NVD
CVE-2026-87935High· 8.1
4d ago

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_…

Twilightichurakov · Paid DownloadsEPSS 0.53%via NVD
CVE-2026-87796Critical· 9.8PoC
4d ago

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…

Abyssalsh1zen · Multi Uploader for Gravity FormsEPSS 0.61%via NVD
CVE-2026-76552High· 8.8
5d ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files…

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files…

TwilightEPSS 0.68%via NVD
CVE-2026-78088High· 8.8
5d ago

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

Twilightcontest-gallery · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeEPSS 0.60%via NVD
CVE-2026-92247Medium· 4.7PoC
5d ago

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload.…

Twilightsynaptikcms · synaptik-cmsEPSS 0.29%via NVD
CVE-2026-81240High· 8.6
6d ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

Twilightdell · wyse_management_suiteEPSS 0.36%via NVD
CVE-2026-81239High· 8.6
6d ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

Twilightdell · wyse_management_suiteEPSS 0.36%via NVD
CVE-2026-81236High· 8.6
6d ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

Twilightdell · wyse_management_suiteEPSS 0.36%via NVD
CVE-2026-91849Medium· 6.3PoC
6d ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

TwilightEPSS 0.27%via NVD
CVE-2026-91005Medium· 6.3
6d ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of t…

SunlitSourceCodester · Online Faculty Clearance SystemEPSS 0.21%via NVD
CVE-2026-90857Medium· 6.3PoC
6d ago

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument…

TwilightSourceCodester · College Notes Gallery Management SystemEPSS 0.21%via NVD
CVE-2026-57581Medium· 5.3
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMi…

Sunlitriganti · dotvvmEPSS 0.44%via NVD
CVE-2023-34854Medium· 6.6
1w ago

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

Sunlitdigitaldruid · HotelDruidEPSS 0.23%via NVD
CVE-2026-82780High· 8.8
1w ago

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.

TwilightContec Co., Ltd · CPS-TM341G5MB-ADSC1-931EPSS 0.34%via NVD
CVE-2026-82793High· 7.2
1w ago

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed o…

TwilightContec Co., Ltd. · CAN-2-WFEPSS 0.35%via NVD
CVE-2026-54177Medium· 6.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFi…

SunlitLaravel-Backpack · CRUDEPSS 0.69%via NVD
CVE-2026-54567High· 7.5PoC
1w ago

Flask-Reuploaded provides file uploads for Flask

Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension hel…

Midnightjugmac00 · flask-reuploadedEPSS 0.58%via NVD
CWE-434 vulnerabilities (CVEs) · VulnSea