Skip to main content

CWE archive

CWE-434 CVEs

Programmatic archive

4,264 CVEs tagged with CWE-4341,503 Critical, 1,635 High, 885 Medium, 240 Low, 1 Unrated.

CVE-2026-63228

Published Jul 29, 2026

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail registrati…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-63227

Published Jul 29, 2026

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessibl…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12476

Published Jul 29, 2026

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in t…

CVSS 7.2 · High
evidence mentions
9
Buzz score
34.5

CVE-2026-13714

Published Jul 27, 2026

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-10818

Published Jul 25, 2026

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due…

CVSS 8.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-24727

Published Jul 24, 2026

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote au…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65461

Published Jul 23, 2026

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65455

Published Jul 23, 2026

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-27064

Published Jul 23, 2026

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-14282

Published Jul 23, 2026

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versio…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
34.5

CVE-2026-63048

Published Jul 22, 2026

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload,…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-16451

Published Jul 21, 2026

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-16447

Published Jul 21, 2026

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument File…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16332

Published Jul 21, 2026

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16331

Published Jul 21, 2026

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Mal…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16330

Published Jul 21, 2026

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argume…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16329

Published Jul 21, 2026

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Han…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16327

Published Jul 21, 2026

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument F…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16324

Published Jul 20, 2026

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-53593

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restri…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61900

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file up…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-61424

Published Jul 20, 2026

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated f…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
25.0
Public PoC observed

CVE-2026-60032

Published Jul 20, 2026

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, le…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63429

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` re…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45797

Published Jul 20, 2026

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored i…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
16.0
Showing 51-75 of 4,264 CVEsPage 3 of 171