Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-434'

View all threats tagged with 'cwe-434'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-434

Threats Tagged 'cwe-434'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19210: Unrestricted Upload in SourceCodester Photo Share WebsiteCVE-2026-19210
0

SourceCodester Photo Share Website 1.0 contains a vulnerability in the /social/ajax.php?action=save_upload endpoint. Manipulation of the img[] or imgName[] arguments allows unrestricted file upload. The vulnerability can be exploited remotely and public exploit details are available. No patch or remediation information is currently provided.

Join the discussion
CVE-2026-19065: Unrestricted Upload in SourceCodester Online Examination & Learning Management SystemCVE-2026-19065
0

A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely.

Join the discussion
CVE-2026-71434: CWE-434: Unrestricted Upload of File with Dangerous Type in statamic cmsCVE-2026-71434
0

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload restrictions that the Control Panel enforces, so an unauthenticated visitor could upload file types an administrator had intended to disallow through a form's assets or files field, and for assets fields, files could be stored on a public, web-accessible disk, though the application's global upload allowlist still blocked executable types such as .php and .html. This issue is fixed in versions 5.74.3 and 6.24.2.

Join the discussion
CVE-2026-70558: CWE-434 Unrestricted upload of file with dangerous type in DataLinkDC DinkyCVE-2026-70558
0

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded in source and shipped to every deployment. Anyone who can reach Dinky's HTTP port (8888 by default) and supplies the hardcoded token can write arbitrary files as the Dinky service account. The default Docker image runs on 8888 with no proxy or authentication and chmod 777 on /opt/dinky, so the application's own classpath, launch scripts, and static assets are writable. Demonstrated impact: overwriting /opt/dinky/config/static/index.html served attacker JavaScript to admin browsers immediately, and writing /opt/dinky/org/dinky/Dinky.class executed attacker code as the Dinky service account at the next JVM start via a classpath-shadow launched by script/bin/auto.sh. Writes are uid 9999 (flink), not root, so /etc, /root, /home, and /usr are refused. Affects Dinky v1.2.5 (the current release) and the development branch, where the code is byte-identical.

Join the discussion
CVE-2026-3418: CWE-434: Unrestricted Upload of File with Dangerous Type in WSO2 WSO2 API ManagerCVE-2026-3418
0

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Depending on the deployment environment and how uploaded files are handled, this could lead to the execution of uploaded content, potentially resulting in remote code execution.

Join the discussion
CVE-2026-18969: Unrestricted Upload in Rongzhitong Visual Integrated Command and Dispatch PlatformCVE-2026-18969
0

A vulnerability in Rongzhitong Visual Integrated Command and Dispatch Platform up to version 20260617 allows remote attackers to perform unrestricted file uploads via manipulation of the File argument in the /dm/dispatch/userinfo/upload endpoint. The vulnerability has a CVSS 3.1 score of 7.3, indicating a medium severity. The vendor was contacted but did not respond, and no patch or remediation information is currently available. Exploit code is publicly available but no known exploitation in the wild has been reported.

Join the discussion
CVE-2026-66665: CWE-434 Unrestricted Upload of File with Dangerous Type in Brandexponents Type HubCVE-2026-66665
0

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

Join the discussion
CVE-2026-6147: CWE-434 Unrestricted Upload of File with Dangerous Type in lightsyncpro LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & ShutterstockCVE-2026-6147
0

The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Join the discussion
CVE-2026-54416: CWE-434 Unrestricted Upload of File with Dangerous Type in pluck-cms Pluck CMSCVE-2026-54416
0

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution.

Join the discussion
CVE-2026-14553: CWE-434 Unrestricted Upload of File with Dangerous Type in zportalsCVE-2026-14553
0

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the original file extension, allowing any authenticated user (Subscriber or higher) to upload arbitrary PHP files and achieve remote code execution.

Join the discussion

Showing 1 to 10 of 54 results

Filters:Tag: cwe-434
Page 1 of 6
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses