Vulnerabilities (CVE)

Filtered by CWE-434
Total 4396 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-56058 2026-06-26 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
CVE-2026-57658 2026-06-26 N/A 9.1 CRITICAL
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
CVE-2026-56059 2026-06-26 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
CVE-2026-56027 2026-06-26 N/A 9.9 CRITICAL
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
CVE-2025-59872 1 Hcltech 1 Zie For Web 2026-06-26 N/A 4.3 MEDIUM
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or operating system commands. For this attack to be successful, the file needs to be uploaded inside the Webroot, and the server must be configured to execute the code
CVE-2019-19576 2 Joomlaworks, Verot Project 2 K2, Verot 2026-06-26 7.5 HIGH 9.8 CRITICAL
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
CVE-2019-19634 2 Joomlaworks, Verot Project 2 K2, Verot 2026-06-26 7.5 HIGH 9.8 CRITICAL
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
CVE-2026-53948 2026-06-25 N/A 5.4 MEDIUM
Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as the site, this could have been used to facilitate stored cross-site scripting against site visitors or staff. This vulnerability is fixed in 6.21.1.
CVE-2022-2356 1 Mediajedi 1 User Private Files 2026-06-23 N/A 8.8 HIGH
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
CVE-2024-25674 1 Misp-project 1 Misp 2026-06-22 N/A 9.8 CRITICAL
An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.
CVE-2024-29859 1 Misp-project 1 Misp 2026-06-22 N/A 9.8 CRITICAL
In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.
CVE-2026-9860 2026-06-18 N/A 8.8 HIGH
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() does not strip single quotes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing — allowing a single quote in the account-id or api-key parameter to break out of the single-quoted PHP string literal in the write_config() define() statement. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. This is possible because the 'cf-images-nonce' nonce required by the AJAX handler is exposed to all Author-level and above users on wp-admin/upload.php via the CFImages JavaScript object, meaning any upload-capable user can satisfy the nonce check and reach the vulnerable wp-config.php write path.
CVE-2025-13590 1 Wso2 4 Api Control Plane, Api Manager, Traffic Manager and 1 more 2026-06-18 N/A 9.1 CRITICAL
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
CVE-2026-52705 2026-06-17 N/A 9.0 CRITICAL
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-40748 2026-06-17 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.
CVE-2026-40746 2026-06-17 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.
CVE-2026-25446 2026-06-17 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
CVE-2025-69129 2026-06-17 N/A 10.0 CRITICAL
Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
CVE-2025-60218 2026-06-17 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.
CVE-2024-52488 2026-06-17 N/A 9.9 CRITICAL
Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.