CVEbaza.plCWE DictionaryCWE-434
Common Weakness Enumeration

CWE-434

Unrestricted Upload of File with Dangerous Type

Category: BaseCVE: 5,184
Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

CVE vulnerabilities with CWE-434 (5,184)
10.0
CVSS
CRITICAL
CVE-2026-4357

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

pub. 2026-09-02
10.0
CVSS
CRITICAL
CVE-2026-84147

This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and compromise the targeted system.

pub. 2026-09-01
10.0
CVSS
CRITICAL
CVE-2026-81780

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

pub. 2026-08-31
10.0
CVSS
CRITICAL
CVE-2026-82970

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

pub. 2026-08-31
10.0
CVSS
CRITICAL
CVE-2026-74803

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-75949

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also missing on upload/remove.

pub. 2026-08-19
10.0
CVSS
CRITICAL
CVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

pub. 2026-08-06
10.0
CVSS
CRITICAL
CVE-2026-61424

The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

pub. 2026-07-20
10.0
CVSS
CRITICAL
CVE-2026-61900

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

pub. 2026-07-20
10.0
CVSS
CRITICAL
CVE-2026-57719

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

pub. 2026-07-13
10.0
CVSS
CRITICAL
CVE-2026-57827

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

pub. 2026-07-11
10.0
CVSS
CRITICAL
CVE-2026-56291

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

pub. 2026-07-09🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2026-48276

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

pub. 2026-06-30
10.0
CVSS
CRITICAL
CVE-2026-48283

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

pub. 2026-06-30
10.0
CVSS
CRITICAL
CVE-2026-56290

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

pub. 2026-06-29🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

pub. 2026-06-25
10.0
CVSS
CRITICAL
CVE-2026-48908

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

pub. 2026-06-20🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2026-48939

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

pub. 2026-06-20🚩 CISA KEV⚡ EXPLOIT
10.0
CVSS
CRITICAL
CVE-2026-40772

Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

pub. 2026-06-15
10.0
CVSS
CRITICAL
CVE-2026-40412

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

pub. 2026-05-22
Showing 20 of 5,184 vulnerabilities
Information
ID: CWE-434
Type: Base
Vulnerabilities: 5,184
MITRE CWE ↗
← CWE Dictionary