Unrestricted Upload of Dangerous File Type

CWE-434 · 10 records · 4 with a public proof-of-concept

Records the NVD classes as Unrestricted Upload of Dangerous File Type (CWE-434), highest CVSS first.

  1. CRITICAL 9.8CVE-2026-14175

    Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.8CVE-2026-16618

    The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to u

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.8CVE-2026-6147

    The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.1CVE-2026-14553

    The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.3CVE-2026-18788public PoC

    A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The expl

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.2CVE-2026-18933

    The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.2CVE-2026-54416public PoC

    Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.2CVE-2026-67243public PoC

    freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may upload an executable file and execute arbitrary OS commands.

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5.4CVE-2026-16548

    The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-65986public PoC

    CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets. When CVAT serves the files attached to an annotation guide,

    AI risk analysis on Exploit-DB.ai →