Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,213 CVEs tagged with CWE-4341,486 Critical, 1,615 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2026-13714

Published Jul 27, 2026

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10818

Published Jul 25, 2026

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-24727

Published Jul 24, 2026

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65461

Published Jul 23, 2026

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65455

Published Jul 23, 2026

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-27064

Published Jul 23, 2026

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-14282

Published Jul 23, 2026

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versio…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
28.5

CVE-2026-63048

Published Jul 22, 2026

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload,…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-16451

Published Jul 21, 2026

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-16447

Published Jul 21, 2026

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument File…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16332

Published Jul 21, 2026

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16331

Published Jul 21, 2026

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Mal…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16330

Published Jul 21, 2026

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argume…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16329

Published Jul 21, 2026

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Han…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16327

Published Jul 21, 2026

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument F…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16324

Published Jul 20, 2026

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-53593

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restri…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61900

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file up…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61424

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated f…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-60032

Published Jul 20, 2026

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, le…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63429

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` re…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45797

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored i…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-57311

Published Jul 20, 2026

Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. Because vendor c…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-16226

Published Jul 19, 2026

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation o…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-48062

Published Jul 17, 2026

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed ex…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 4,213 CVEsPage 1 of 169