Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,214 CVEs tagged with CWE-4341,486 Critical, 1,616 High, 875 Medium, 236 Low, 1 Unrated.

CVE-2026-48062

Published Jul 17, 2026

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed ex…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-36669

Published Jul 17, 2026

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-13352

Published Jul 17, 2026

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Uplo…

CVSS 8.8 · High
evidence mentions
9
Buzz score
34.5

CVE-2026-12684

Published Jul 16, 2026

The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50124

Published Jul 15, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/uplo…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-61457

Published Jul 15, 2026

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspec…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-11579

Published Jul 15, 2026

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upl…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15677

Published Jul 14, 2026

A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-58409

Published Jul 13, 2026

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-49972

Published Jul 13, 2026

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-14906

Published Jul 13, 2026

Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-57719

Published Jul 13, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a throu…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-57710

Published Jul 13, 2026

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-15539

Published Jul 13, 2026

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-15553

Published Jul 13, 2026

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15518

Published Jul 13, 2026

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileL…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
34.5

CVE-2026-15488

Published Jul 12, 2026

A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-61448

Published Jul 11, 2026

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recogn…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-57828

Published Jul 11, 2026

Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-57827

Published Jul 11, 2026

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file uplo…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2354

Published Jul 11, 2026

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all…

CVSS 8.8 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-15282

Published Jul 10, 2026

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.6
Public PoC observed

CVE-2026-14894

Published Jul 10, 2026

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function.…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
33.4
Public PoC observed

CVE-2026-13430

Published Jul 10, 2026

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure functio…

CVSS 7.2 · High
evidence mentions
8
Buzz score
33.5
Showing 26-50 of 4,214 CVEsPage 2 of 169