Vulnerabilities (CVE)

Filtered by CWE-434
Total 4396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-56218 1 Ascertia 1 Signinghub 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2025-55835 1 Sueamcms Project 1 Sueamcms 2026-07-05 N/A 9.8 CRITICAL
File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.
CVE-2025-52239 1 Zkea 1 Zkeacms 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2025-46157 1 Efrotech 1 Timetrax 2026-07-05 N/A 9.9 CRITICAL
An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form
CVE-2024-48734 2026-07-05 N/A 8.8 HIGH
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users.
CVE-2026-36387 2026-07-05 N/A 6.5 MEDIUM
A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanitization allows attackers to inject malicious files which leads RCE.
CVE-2025-63748 1 Testmanagement 1 Qatraq 2026-07-05 N/A 8.8 HIGH
QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" module. The application fails to restrict file types, enabling the upload of executable PHP files. Once uploaded, the file can be accessed through the "View Attachment" option, which executes the PHP payload on the server.
CVE-2025-60735 1 Perfree 1 Perfreeblog 2026-07-05 N/A 7.6 HIGH
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function
CVE-2025-60731 1 Perfree 1 Perfreeblog 2026-07-05 N/A 7.6 HIGH
PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function
CVE-2025-56704 1 Lepton-cms 1 Leptoncms 2026-07-05 N/A 8.8 HIGH
LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validation for uploaded files. An authenticated attacker can exploit this vulnerability by uploading a specially crafted ZIP/PHP file to execute arbitrary code.
CVE-2025-56295 1 Carmelo 1 Computer Laboratory System 2026-07-05 N/A 7.3 HIGH
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by uploading PHP backdoor files when modifying personal avatar information and use web shell connection tools to obtain server permissions.
CVE-2024-44599 1 Fntsoftware 1 Fnt Command 2026-07-05 N/A 8.3 HIGH
FNT Command 13.4.0 is vulnerable to Directory Traversal.
CVE-2024-44598 1 Fntsoftware 1 Fnt Command 2026-07-05 N/A 8.8 HIGH
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
CVE-2025-52078 2026-07-05 N/A 6.5 MEDIUM
File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.
CVE-2025-51056 1 Vedo Suite Project 1 Vedo Suite 2026-07-05 N/A 8.2 HIGH
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write to arbitrary filesystem paths by exploiting the insecure 'uploadPreviews()' custom function in '/api_vedo/colorways_preview', ultimately resulting in remote code execution (RCE).
CVE-2025-46099 1 Pluck-cms 1 Pluck 2026-07-05 N/A 7.2 HIGH
In Pluck CMS 4.7.20-dev, an authenticated attacker can upload or create a crafted PHP file under the albums module directory and access it via the module routing logic in albums.site.php, resulting in arbitrary command execution through a GET parameter.
CVE-2025-44139 1 Emlog 1 Emlog 2026-07-05 N/A 7.2 HIGH
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upload_zip
CVE-2025-29287 1 Mingsoft 1 Mcms 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-25790 1 Foxcms 1 Foxcms 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2025-25784 1 Jizhicms 1 Jizhicms 2026-07-05 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.