VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

232 CVEsRSS

CVE-2026-50768High· 8.8
1mo ago

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

▾ TwilightEPSS 0.66%via NVD
CVE-2026-16098Critical· 9.8
1mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Con…

▾ MidnightEPSS 1.2%via NVD
CVE-2026-14498High· 8.8
1mo ago

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_a…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-74767None
1mo ago

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from a DAA archive, compressed chunks were decompressed using zlib.decompress() without enfor…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-18438High· 8.8
1mo ago

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file functi…

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file functi…

▾ TwilightEPSS 1.3%via NVD
CVE-2026-49827Critical· 9.8
1mo ago

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote …

▾ MidnightEPSS 0.86%via NVD
CVE-2026-65939Medium· 6.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

▾ SunlitEPSS 0.38%via NVD
CVE-2026-55676High· 8.8
1mo ago

Malcolm is a network traffic analysis tool suite

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-l…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-72762High· 8.8
1mo ago

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user abl…

▾ Twilightn8n · n8nEPSS 0.48%via NVD
CVE-2026-72592Critical· 9.8
1mo ago

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and n…

▾ MidnightEPSS 0.80%via NVD
CVE-2026-19383Medium· 4.7
1mo ago

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unre…

▾ SunlitEPSS 0.38%via NVD
CVE-2022-4995Critical· 9.8
1mo ago

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request …

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request …

▾ MidnightEPSS 1.2%via NVD
CVE-2026-3418Critical· 9.1
1mo ago

Arbitrary File Upload via System REST API in Multiple WSO2 Products Allows Remote Code Execution

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated ad…

▾ MidnightWSO2 · WSO2 API ManagerEPSS 0.76%via CVEORG
CVE-2026-70558Critical· 9.8
1mo ago

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from th…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-71434Medium· 5.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could up…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-54416High· 7.2
1mo ago

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.…

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-65986None
1mo ago

CVAT is an open source interactive video and image annotation tool for computer vision

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached t…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-53948Medium· 5.4
1mo ago

Ghost: File Upload Content-Type Spoofing

Ghost: File Upload Content-Type Spoofing

▾ Sunlitghost · ghostEPSS 0.23%via GHSA
CVE-2026-61524High· 7.2
1mo ago

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing…

WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-63223Critical· 9.8PoC
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when a…

▾ AbyssalEPSS 0.80%via NVD
CVE-2026-53599High· 7.5
1mo ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/…

▾ Twilightredaxo · redaxo/sourceEPSS 0.51%via NVD
CVE-2026-58428Medium· 6.5
2mo ago

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.46%via GHSA
CVE-2026-16226Medium· 4.7
2mo ago

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack …

▾ SunlitEPSS 0.38%via NVD
GHSA-hgjx-r89m-m7v4Critical· 9.9
2mo ago

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE

▾ Midnightfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-15539Medium· 4.7
2mo ago

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unr…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-15553Medium· 5.3
2mo ago

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-15518Medium· 4.7
2mo ago

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-15488High· 7.3
2mo ago

A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3

A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestric…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-61448None
2mo ago

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the clien…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-57828None
2mo ago

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

▾ SunlitEPSS 0.54%via NVD
CWE-434 vulnerabilities (CVEs) — page 4 · VulnSea