Threats Tagged 'cwe-434'
View all threats tagged with 'cwe-434'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-434'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54414: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in error311 FileRiseCVE-2026-54414 0 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to UploadModel::handleUpload, where it is reconstructed as trim(urldecode(basename($fileName))), re-introducing path separators after validation (e.g. ..%2fusers%2fusers.txt becomes ../users/users.txt). UploadNamePolicy::isAllowedForWrite() applies basename() internally and therefore only evaluates the final component (users.txt), allowing the traversal sequence to pass the extension policy. The destination path is then used directly in move_uploaded_file() with no realpath containment check, allowing a write outside the intended upload directory. An attacker who possesses a valid, non-expired, upload-enabled shared-folder link/token (which are designed to be shared publicly) can overwrite users/users.txt to create an administrator account, resulting in unauthenticated admin takeover and, depending on configuration, remote code execution. Exploitation requires possession of a valid, non-expired, upload-enabled shared-folder link/token. This issue is fixed in 3.16.0, which URL-decodes before validation and rejects any path separators in the upload filename. Join the discussion | CVE Database V5 | 06/19/2026, 05:41:44 UTC Added: 06/19/2026, 06:20:09 UTC |
CVE-2026-9815: CWE-434 Unrestricted Upload of File with Dangerous Type in MagicFormCVE-2026-9815 0 The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server. Join the discussion | CVE Database V5 | 06/18/2026, 06:00:02 UTC Added: 06/18/2026, 07:36:01 UTC |
CVE-2026-9860: CWE-434 Unrestricted Upload of File with Dangerous Type in vanyukov Offload, AI & Optimize with Cloudflare ImagesCVE-2026-9860 0 The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler, which requires only the upload_files capability (Author+) rather than manage_options before writing to wp-config.php, combined with the absence of single-quote escaping — sanitize_text_field() does not strip single quotes, and filter_input(INPUT_POST) bypasses wp_magic_quotes() slashing — allowing a single quote in the account-id or api-key parameter to break out of the single-quoted PHP string literal in the write_config() define() statement. This makes it possible for authenticated attackers, with author-level access and above, to execute code on the server. This is possible because the 'cf-images-nonce' nonce required by the AJAX handler is exposed to all Author-level and above users on wp-admin/upload.php via the CFImages JavaScript object, meaning any upload-capable user can satisfy the nonce check and reach the vulnerable wp-config.php write path. Join the discussion | CVE Database V5 | 06/18/2026, 04:31:08 UTC Added: 06/18/2026, 05:51:23 UTC |
CVE-2026-52705: CWE-434 Unrestricted Upload of File with Dangerous Type in BDthemes SigmaForms Pro – AI Generated FormsCVE-2026-52705 0 CVE-2026-52705 is a critical vulnerability in BDthemes SigmaForms Pro – AI Generated Forms versions up to and including 1.4.5. It allows unauthenticated attackers to upload arbitrary files of dangerous types, leading to potential full compromise of confidentiality, integrity, and availability. The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). No official patch or remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:31 UTC Added: 06/17/2026, 11:09:06 UTC |
CVE-2026-40749: CWE-434 Unrestricted Upload of File with Dangerous Type in themagnifico52 Charity ZoneCVE-2026-40749 0 Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:06 UTC Added: 06/17/2026, 11:08:57 UTC |
CVE-2026-40748: CWE-434 Unrestricted Upload of File with Dangerous Type in themagnifico52 Kids Gift ShopCVE-2026-40748 0 CVE-2026-40748 is a critical vulnerability in themagnifico52 Kids Gift Shop versions up to 0.5.4 that allows subscribers to upload arbitrary files without restriction on file type. This unrestricted file upload can lead to severe consequences including full system compromise. The vulnerability is classified under CWE-434, indicating unsafe handling of file uploads. No official patch or remediation has been confirmed yet. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:05 UTC Added: 06/17/2026, 11:08:57 UTC |
CVE-2026-40747: CWE-434 Unrestricted Upload of File with Dangerous Type in themagnifico52 Ecommerce ZoneCVE-2026-40747 0 Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:04 UTC Added: 06/17/2026, 11:08:57 UTC |
CVE-2026-40746: CWE-434 Unrestricted Upload of File with Dangerous Type in themagnifico52 Restaurant ZoneCVE-2026-40746 0 CVE-2026-40746 is a critical vulnerability in themagnifico52's Restaurant Zone product, versions up to and including 0.7.8. It allows subscribers to upload arbitrary files without restriction on file type, which can lead to severe consequences including full system compromise. The vulnerability is classified under CWE-434, indicating unrestricted file upload of dangerous types. No official patch or remediation has been confirmed yet. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:03 UTC Added: 06/17/2026, 11:08:57 UTC |
CVE-2026-39589: CWE-434 Unrestricted Upload of File with Dangerous Type in A WP Life WebenvoCVE-2026-39589 0 Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:50:52 UTC Added: 06/17/2026, 11:08:54 UTC |
CVE-2026-27041: CWE-434 Unrestricted Upload of File with Dangerous Type in Studio Keren Aga LTD. Unlimited Elements for Elementor (Premium)CVE-2026-27041 0 Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:50:43 UTC Added: 06/17/2026, 11:08:48 UTC |
Showing 1 to 10 of 44 results