← Back to feed Search feed

CWE-434 Unrestricted File Upload vulnerabilities

37 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-81402The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type vCRITICAL9.838%ileNVD2026-09-12
CVE-2026-84171The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files beforeCRITICAL9.831%ileNVD2026-09-12
CVE-2026-87796The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, CRITICAL9.848%ileNVD2026-09-17
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote aCRITICAL9.861%ileNVD2026-09-17
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL froCRITICAL9.154%ileNVD2026-09-14
CVE-2026-83163Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / FileHIGH8.836%ileNVD2026-09-15
CVE-2026-78088The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to UnautHIGH8.847%ileNVD2026-09-16
CVE-2026-76552The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it reHIGH8.851%ileNVD2026-09-16
CVE-2026-86801The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress anHIGH8.827%ileNVD2026-09-17
CVE-2026-93031The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable HIGH8.8NVD2026-09-18
CVE-2026-82780Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploHIGH8.727%ileNVD2026-09-14
CVE-2026-92970HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticHIGH8.743%ileNVD2026-09-17
CVE-2026-77929ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote cHIGH8.7NVD2026-09-18
CVE-2026-82793Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB ConvertHIGH8.629%ileNVD2026-09-14
CVE-2026-81236Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%ileNVD2026-09-15
CVE-2026-81239Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%ileNVD2026-09-15
CVE-2026-81240Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%ileNVD2026-09-15
CVE-2026-92980HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administratoHIGH8.644%ileNVD2026-09-17
CVE-2026-87935The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1HIGH8.144%ileNVD2026-09-17
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFieHIGH7.623%ileNVD2026-09-14
CVE-2026-54567Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flaskHIGH7.547%ileNVD2026-09-14
CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate theHIGH7.219%ileNVD2026-09-12
CVE-2026-90603A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknMEDIUM6.940%ileNVD2026-09-13
CVE-2023-34854HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.MEDIUM6.614%ileNVD2026-09-14
CVE-2026-54177backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM6.651%ileNVD2026-09-14
CVE-2026-886181024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This MEDIUM6.523%ileNVD2026-09-15
CVE-2026-56590HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation cMEDIUM6.47%ileNVD2026-09-18
CVE-2026-84048Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < MEDIUM6.324%ileNVD2026-09-15
CVE-2026-86861pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested patMEDIUM6.038%ileNVD2026-09-17
CVE-2026-57581DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applicMEDIUM5.338%ileNVD2026-09-14
CVE-2026-93506A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/MEDIUM5.3NVD2026-09-18
CVE-2026-90500A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload ofLOW2.110%ileNVD2026-09-13
CVE-2026-90519A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the fLOW2.112%ileNVD2026-09-13
CVE-2026-90857A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown functLOW2.112%ileNVD2026-09-15
CVE-2026-91005A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploadedLOW2.112%ileNVD2026-09-15
CVE-2026-91849A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /inLOW2.120%ileNVD2026-09-15
CVE-2026-92247A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename oLOW2.022%ileNVD2026-09-16