VulnSea

CWE-434

CVEs classified under CWE-434, newest first.

232 CVEsRSS

CVE-2026-57827NonePoC
2mo ago

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ TwilightEPSS 2.3%via NVD
CVE-2026-2354High· 8.8
2mo ago

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extensio…

▾ TwilightEPSS 1.00%via NVD
CVE-2026-13430High· 7.2
2mo ago

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation c…

▾ TwilightEPSS 1.1%via NVD
GHSA-qv4m-m73m-8hj7High· 8.8
2mo ago

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

▾ Twilightnotrinos · notrinos/notrinos-erpvia GHSA
CVE-2026-56291Critical· 9.8CISA KEV0dayPoC
2mo ago

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadalbalbooa · formsEPSS 15%via NVD
CVE-2026-56290Critical· 9.8CISA KEVPoC
3mo ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadaljoomlack · page_builder_ckEPSS 31%via NVD
CVE-2026-48946Medium· 6.3
3mo ago

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user

The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/a…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-48945Medium· 5.3
3mo ago

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and …

The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and …

▾ SunlitEPSS 0.33%via NVD
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-48939Critical· 9.8CISA KEVPoC
3mo ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

▾ Hadaljoomlic · icagendaEPSS 20%via NVD
CVE-2026-54414Critical· 9.8
3mo ago

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by F…

▾ MidnightEPSS 0.66%via NVD
GHSA-2rm3-333w-xvc4Medium· 5.3
3mo ago

DotVVM: Unrestricted file upload

DotVVM: Unrestricted file upload

▾ SunlitDotVVM · DotVVMvia GHSA
CVE-2026-53724Low
3mo ago

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.49%via GHSA
CVE-2026-55778Low
3mo ago

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist

▾ Sunlitparse-server · parse-serverEPSS 0.55%via GHSA
CVE-2026-48062Critical· 9.8
3mo ago

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule

▾ Midnightcodeigniter4 · codeigniter4/frameworkEPSS 0.78%via GHSA
CVE-2026-40412Critical· 10.0
4mo ago

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · azure_orbital_spatioEPSS 0.97%via NVD
CVE-2026-2942Critical· 9.8PoC
5mo ago

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for…

▾ AbyssalEPSS 1.1%via NVD
CVE-2026-33273High· 7.2
5mo ago

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be…

▾ Twilighticz · matcha_invoiceEPSS 0.41%via NVD
CVE-2026-5704Medium· 5.0
5mo ago

A flaw was found in tar

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, pot…

▾ Sunlitgnu · tarEPSS 0.40%via NVD
CVE-2016-20052Critical· 9.8
5mo ago

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the…

▾ Midnightsnewscms · snewsEPSS 0.95%via NVD
CVE-2026-4809Critical· 9.8
6mo ago

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote atta…

▾ MidnightEPSS 1.1%via NVD
CVE-2025-13462Low· 3.3
6mo ago

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinter…

▾ Sunlitpython · pythonEPSS 0.16%via NVD
CVE-2025-70151High· 8.8PoC
7mo ago

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-acce…

▾ Midnightfabian · scholars_tracking_systemEPSS 0.70%via NVD
CVE-2025-65783Critical· 9.8
8mo ago

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

▾ Midnighthubert · hubEPSS 0.52%via NVD
CVE-2025-67707Medium· 5.6
9mo ago

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the s…

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the s…

▾ Sunlitesri · arcgis_serverEPSS 0.30%via NVD
CVE-2025-67706Medium· 5.6
9mo ago

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the s…

ArcGIS Server versions 11.5 and earlier on Windows and Linux do not sufficiently validate uploaded files, enabling a remote unauthenticated attacker to upload arbitrary files to the server’s designated upload directories. However, the s…

▾ Sunlitesri · arcgis_serverEPSS 0.35%via NVD
CVE-2025-67288Critical· 10.0
9mo ago

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in …

▾ Midnightumbraco · umbraco_cmsEPSS 0.55%via NVD
CVE-2025-67289Critical· 9.6
9mo ago

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

▾ Midnightfrappe · erpnextEPSS 0.46%via NVD
CVE-2024-58283High· 8.8
9mo ago

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager

WBCE CMS version 1.6.2 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the Elfinder file manager. Attackers can exploit the file upload functionality in the elfinde…

▾ Twilightwbce · wbce_cmsEPSS 0.66%via NVD
CVE-2024-58282High· 7.2
9mo ago

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality

Serendipity 2.5.0 contains a remote code execution vulnerability that allows authenticated administrators to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload mechanism by creating a…

▾ Twilights9y · serendipityEPSS 1.0%via NVD
CWE-434 vulnerabilities (CVEs) — page 5 · VulnSea