VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

232 CVEsRSS

CVE-2026-45140Critical· 9.8PoC
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

▾ Abyssalchamilo · chamilo-lmsEPSS 1.3%via NVD
CVE-2026-92980High· 7.2
1w ago

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality

HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary OS commands as the web server user by abusing the Import/Export functionality. Attackers can …

▾ Twilightdanielbrendel · hortusfox-webEPSS 0.98%via NVD
CVE-2026-87935High· 8.1
1w ago

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_…

▾ Twilightichurakov · Paid DownloadsEPSS 0.91%via NVD
CVE-2026-87796Critical· 9.8PoC
1w ago

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…

▾ Abyssalsh1zen · Multi Uploader for Gravity FormsEPSS 1.1%via NVD
CVE-2026-76552High· 8.8
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files…

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files…

▾ TwilightEPSS 0.73%via NVD
CVE-2026-78088High· 8.8
1w ago

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path valida…

▾ Twilightcontest-gallery · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & StripeEPSS 0.79%via NVD
CVE-2026-92247Medium· 4.7PoC
1w ago

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload.…

▾ Twilightsynaptikcms · synaptik-cmsEPSS 0.40%via NVD
CVE-2026-81240High· 8.6
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.40%via NVD
CVE-2026-81239High· 8.6
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.40%via NVD
CVE-2026-81236High· 8.6
1w ago

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to…

▾ Twilightdell · wyse_management_suiteEPSS 0.41%via NVD
CVE-2026-91849Medium· 6.3PoC
1w ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

▾ TwilightEPSS 0.37%via NVD
CVE-2026-91005Medium· 6.3
1w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of t…

▾ SunlitSourceCodester · Online Faculty Clearance SystemEPSS 0.37%via NVD
CVE-2026-90857Medium· 6.3PoC
1w ago

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument…

▾ TwilightSourceCodester · College Notes Gallery Management SystemEPSS 0.37%via NVD
CVE-2026-57581Medium· 5.3
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMi…

▾ Sunlitriganti · dotvvmEPSS 0.59%via NVD
CVE-2023-34854Medium· 6.6
1w ago

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

▾ Sunlitdigitaldruid · HotelDruidEPSS 0.23%via NVD
CVE-2026-82780High· 8.8
1w ago

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.

▾ TwilightContec Co., Ltd · CPS-TM341G5MB-ADSC1-931EPSS 0.61%via NVD
CVE-2026-82793High· 7.2
1w ago

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed o…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 0.63%via NVD
CVE-2026-54177Medium· 6.6
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFi…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.93%via NVD
CVE-2026-54567High· 7.5PoC
1w ago

Flask-Reuploaded provides file uploads for Flask

Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension hel…

▾ Midnightjugmac00 · flask-reuploadedEPSS 0.63%via NVD
CVE-2026-54087High· 7.6
1w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…

▾ TwilightEasyCorp · EasyAdminBundleEPSS 0.40%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-90500Medium· 6.3PoC
2w ago

A weakness has been identified in lenve vhr 1.0-SNAPSHOT

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upl…

▾ Twilightlenve · vhrEPSS 0.35%via NVD
CVE-2026-90519Medium· 6.3PoC
2w ago

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remo…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.37%via NVD
CVE-2026-90603High· 7.3
2w ago

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-prox…

▾ TwilightAnil-matcha · Open-Generative-AIEPSS 0.50%via NVD
CVE-2026-84171Critical· 9.8
2w ago

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and ex…

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and ex…

▾ MidnightEPSS 0.67%via NVD
CVE-2026-81402Critical· 9.8
2w ago

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, t…

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, t…

▾ MidnightEPSS 0.81%via NVD
CVE-2026-81090High· 7.2
2w ago

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP v…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-8778Critical· 9.8
2w ago

MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versio…

▾ Midnightmulika · MIPL Grouped Checkout Fields for WooCommerce. Customize & Organize Checkout Fields.EPSS 1.1%via CVEORG
CVE-2026-12215Medium· 5.3
2w ago

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `pro…

▾ Sunlitxootix · OTP Login & Register WoocommerceEPSS 0.32%via NVD
CVE-2026-84063Medium· 6.5
2w ago

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allo…

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.43%via CVEORG
CWE-434 vulnerabilities (CVEs) — page 2 · VulnSea