← Back to feed Search feed

CWE-434 Unrestricted File Upload vulnerabilities

21 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-63227An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORCRITICAL9.925%ileNVD2026-07-29
CVE-2026-16610The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions upCRITICAL9.844%ileNVD2026-07-30
CVE-2026-63223CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not iCRITICAL9.840%ileNVD2026-07-31
CVE-2026-14483The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all verCRITICAL9.846%ileNVD2026-07-31
CVE-2026-14175Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANISCRITICAL9.832%ileNVD2026-08-04
CVE-2026-65885Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows auCRITICAL9.417%ileNVD2026-07-29
CVE-2026-14270The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerablHIGH8.843%ileNVD2026-07-29
CVE-2026-16236The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5HIGH8.847%ileNVD2026-07-31
CVE-2026-67206Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticatHIGH8.736%ileNVD2026-07-30
CVE-2026-39931OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature tHIGH8.625%ileNVD2026-08-03
CVE-2026-61524WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature thHIGH8.643%ileNVD2026-08-03
CVE-2026-67243freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the higHIGH8.622%ileNVD2026-08-04
CVE-2026-53599REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/sHIGH7.524%ileNVD2026-07-31
CVE-2026-18607A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53HIGH7.436%ileNVD2026-08-03
CVE-2026-12476The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3HIGH7.247%ileNVD2026-07-29
CVE-2026-44103An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore MEDIUM6.915%ileNVD2026-07-30
CVE-2026-16548The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin beMEDIUM5.46%ileNVD2026-08-04
CVE-2026-44097A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fiMEDIUM5.316%ileNVD2026-07-30
CVE-2026-21662Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using MalicMEDIUM4.834%ileNVD2026-07-31
CVE-2026-63228An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content LOW2.63%ileNVD2026-07-29
CVE-2026-18682A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /apiLOW1.316%ileNVD2026-08-03