On this page
CWE-434: Unrestricted Upload of File with Dangerous Type
Weakness Summary
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
- Canonical source: MITRE CWE-434 (opens in a new tab)
- Published Atomicorp CVE observations: 144
- Distinct affected products in those observations: 133
- Active Atomicorp rules associated with this weakness: 76
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2024-56064 | WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE | indeed-wp-superbackup | Attack Blocked by Atomicorp | 382238 |
| CVE-2025-34040 | Zhiyuan OA - arbitrary file upload leading | Zhiyuan OA Web Application System | Attack Blocked by Atomicorp | 330791 , 340007 , 340152 |
| CVE-2025-34163 | Dongsheng Logistics Software Unauthenticated Arbitrary File Upload | Dongsheng Logistics Software | Attack Blocked by Atomicorp | 351000 |
| CVE-2025-47577 | TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload | ti-woocommerce-wishlist | Attack Blocked by Atomicorp | 382238 |
| CVE-2026-57827 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 | rsfiles! | Attack Blocked by Atomicorp | 351000 |
| CVE-2019-4013 | IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload | bigfix platform | Attack Blocked by Atomicorp | 392301 |
| CVE-2014-8739 | WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Upload | creative contact form | Attack Blocked by Atomicorp | 300016 |
| CVE-2015-10138 | Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload | work the flow file upload | Attack Blocked by Atomicorp | 351000 |
| CVE-2015-4455 | WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload | aviary image editor add-on for gravity forms | Attack Blocked by Atomicorp | 340007 , 391742 , 391743 |
| CVE-2015-9499 | WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCE | showbiz pro | Attack Blocked by Atomicorp | 300019 , 300029 |
| CVE-2016-15042 | WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload | frontend file manager | Attack Blocked by Atomicorp | 382238 |
| CVE-2016-15043 | WP Mobile Detector <= 3.5 - Unrestricted File Upload | wp mobile detector | Attack Blocked by Atomicorp | 340162 , 340163 , 391740 |
| CVE-2016-3088 | Apache ActiveMQ Fileserver - Arbitrary File Write | activemq | Attack Blocked by Atomicorp | 392301 |
| CVE-2017-16949 | Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload | anonymous post pro | Detected by Atomicorp | 345493 |
| CVE-2017-17976 | PerfexCRM 1.9.7 - Arbitrary File Upload | perfex crm | Attack Blocked by Atomicorp | 392301 |
| CVE-2018-17440 | D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities | central wifimanager | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585 |
| CVE-2018-20526 | Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal | roxy fileman | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2019-10647 | ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE) | zzzphp | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2020-12800 | WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution | drag and drop multiple file upload - contact form 7 | Attack Blocked by Atomicorp | 300018 |
| CVE-2020-25213 | WordPress File Manager Plugin - Remote Code Execution | file manager | Attack Blocked by Atomicorp | 393781 |
| CVE-2021-23394 | elFinder < 2.1.58 - Remote Code Execution | elfinder | Attack Blocked by Atomicorp | 393781 |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | help scout | Attack Blocked by Atomicorp | 330791 , 340152 , 382238 |
| CVE-2021-24284 | WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload | kaswara | Attack Blocked by Atomicorp | 382238 |
| CVE-2021-24499 | WordPress Workreap - Remote Code Execution | workreap | Attack Blocked by Atomicorp | 330791 , 340152 , 382238 |
| CVE-2021-25003 | WordPress WPCargo Track & Trace <6.9.0 - Remote Code Execution | wpcargo track & trace | Detected by Atomicorp | 331324 |
| CVE-2021-30118 | Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code Execution | vsa | Attack Blocked by Atomicorp | 344365 , 392301 |
| CVE-2021-3378 | FortiLogger 4.4.2.2 - Arbitrary File Upload | fortilogger | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2021-34624 | WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload | profilepress | Attack Blocked by Atomicorp | 382238 |
| CVE-2021-43421 | Studio-42 elFinder <2.1.60 - Arbitrary File Upload | elfinder | Attack Blocked by Atomicorp | 393781 |
| CVE-2021-4449 | ZoomSounds Plugin - Unauthenticated Arbitrary File Upload | zoomsounds | Attack Blocked by Atomicorp | 392301 |
| CVE-2022-1952 | WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload | free booking plugin for hotels, restaurant and car rental | Attack Blocked by Atomicorp | 382238 |
| CVE-2022-34128 | GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE) | positions | Attack Blocked by Atomicorp | 392301 |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | learnpress | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2023-2648 | Weaver E-Office 9.5 - Remote Code Execution | e-office | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2023-3722 | Avaya Aura Device Services - OS Command Injection | aura device services | Attack Blocked by Atomicorp | 392301 |
| CVE-2023-37629 | Online Piggery Management System v1.0 - Unauthenticated File Upload | simple online piggery management system | Attack Blocked by Atomicorp | 330791 |
| CVE-2023-4596 | WordPress Plugin Forminator 1.24.6 - Arbitrary File Upload | forminator | Attack Blocked by Atomicorp | 300006 |
| CVE-2023-51409 | Jordy Meow AI Engine - Unrestricted File Upload | ai engine | Attack Blocked by Atomicorp | 382238 |
| CVE-2023-5360 | WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload | royal elementor addons | Attack Blocked by Atomicorp | 382238 |
| CVE-2024-2667 | InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Upload | instawp connect | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2024-50623 | Cleo Harmony < 5.8.0.21 - Arbitary File Read | harmony | Attack Blocked by Atomicorp | 344365 |
| CVE-2024-8425 | WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload | woocommerce ultimate gift card | Attack Blocked by Atomicorp | 382238 |
| CVE-2025-26319 | FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload | flowise | Attack Blocked by Atomicorp | 346019 |
| CVE-2025-31324 | SAP NetWeaver Visual Composer Metadata Uploader - Deserialization | netweaver | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2025-6058 | WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload | wpbookit | Attack Blocked by Atomicorp | 382238 |
| CVE-2025-9314 | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload | The Developer Tools WordPress plugin through 1.1.3 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-0740 | Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload | ninja forms file uploads | Attack Blocked by Atomicorp | 382238 |
| CVE-2026-14894 | WordPress Super Forms <= 6.3.313 - Arbitrary File Upload | super-forms | Attack Blocked by Atomicorp | 340748 |
| CVE-2026-36669 | ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerability | ck upload handler.php in Feng Office 3.11.13.11 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-49827 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | WebErpMesv2 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-50894 | easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability | - | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-67678 | RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution Vulnerability | RainyGao-Hithub DocSys v.2.02.80 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-67688 | ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution Vulnerability | ICS-Park Smart Park Management System v2.0 | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71805 | Path Traversal | - | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-72592 | dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File Upload | phpfm | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75327 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java Arbitrary File Upload Vulnerability | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | joro | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write | on-prem enterprise server | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2016-20052 | Snews CMS 1.7 Unrestricted File Upload via snews_files | snews | Attack Blocked by Atomicorp | 351000 |
| CVE-2018-25114 | osCommerce 2.3.4.1 - Remote Code Execution | Online Merchant | Attack Blocked by Atomicorp | 340023 , 340095 , 344360 , 344370 |
| CVE-2022-4995 | Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jsp | E-cology 9.0 | Attack Blocked by Atomicorp | 351000 |
| CVE-2024-58348 | WordPress Background Image Cropper 1.2 Remote Code Execution | Background Image Cropper | Attack Blocked by Atomicorp | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | SNMP Web Pro | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-70558 | Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default Token | Dinky | Attack Blocked by Atomicorp | 351000 |
| CVE-2023-7305 | SmartBI RMIServlet Unrestricted File Upload RCE | SmartBI | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2021-21351 | XStream <1.4.16 - Remote Code Execution | xstream | Attack Blocked by Atomicorp | 344380 |
| CVE-2026-49849 | xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution | xshop | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-32475 | Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler | Elementor Pro | Detected by Atomicorp | 398001 |
| CVE-2017-6090 | PhpColl 2.5.1 Arbitrary File Upload | phpcollab | Attack Blocked by Atomicorp | 391746 |
| CVE-2018-17442 | D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities | central wifimanager | Attack Blocked by Atomicorp | 340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585 |
| CVE-2019-15813 | Sentrifugo 3.2 - File Upload Restriction Bypass | sentrifugo | Detected by Atomicorp | 345493 |
| CVE-2019-9189 | Prima Access Control 2.3.35 - Arbitrary File Upload | flexair | Attack Blocked by Atomicorp | 342259 , 344360 , 344363 , 344364 , 344366 , 350147 , 390724 , 390726 , 392647 |
| CVE-2020-8639 | TestLink 1.9.20 - Unrestricted File Upload (Authenticated) | testlink | Detected by Atomicorp | 345493 |
| CVE-2022-1329 | Elementor Website Builder - Remote Code Execution | website builder | Detected by Atomicorp | 377360 |
| CVE-2023-48777 | WordPress Elementor 3.18.1 - File Upload/Remote Code Execution | website builder | Detected by Atomicorp | 377360 |
| CVE-2025-59710 | biztalk360 Arbitrary Code Execution Vulnerability | biztalk360 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-70151 | scholars tracking system Arbitrary Code Execution Vulnerability | scholars tracking system | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-55676 | Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component | Malcolm | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-72557 | Cockpit CMS Cockpit CMS - Unrestricted File Upload | Cockpit CMS | Attack Blocked by Atomicorp | 351000 |
| CVE-2018-25409 | SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.php | SIM-PKH | Attack Blocked by Atomicorp | 351000 |
| CVE-2019-25673 | UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File Upload | Laravel File Manager | Attack Blocked by Atomicorp | 351000 |
| CVE-2021-47943 | TextPattern CMS 4.8.7 Remote Code Execution via File Upload | TextPattern CMS | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-34735 | Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileController | wiki | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-67206 | Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload | wolfcms | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2026-68899 | Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback | wekan | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-26212 | Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE | Rara One Click Demo Import | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-39931 | OpenEMR Authenticated SQL Injection via backup.php Import Feature | openemr | Attack Blocked by Atomicorp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63429 | HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context | heyform | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-82524 | UnoPim File Upload RCE via TinyMCE Image Upload Endpoint | unopim | Attack Blocked by Atomicorp | 351000 |
| CVE-2024-24809 | Traccar - Unrestricted File Upload | traccar | Attack Blocked by Atomicorp | 330791 , 340152 , 391213 |
| CVE-2026-65986 | CVAT has stored XSS via annotation guide assets | cvat | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 341256 , 342259 , 350147 , 350148 |
| CVE-2017-12615 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | Attack Blocked by Atomicorp | 337209 , 337210 , 337211 , 340095 , 340128 , 344360 , 345493 , 347009 , 380018 , 380026 , 390904 , 392301 |
| CVE-2017-12617 | Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1) | tomcat | Attack Blocked by Atomicorp | 345493 , 392301 |
| CVE-2026-5718 | Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution | drag-and-drop-multiple-file-upload-contact-form-7 | Attack Blocked by Atomicorp | 382238 |
| CVE-2026-53599 | Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mo | core | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2020-20969 | PluckCMS 4.7.10 - Unrestricted File Upload | pluck | Attack Blocked by Atomicorp | 340035 , 390727 , 392301 , 392648 |
| CVE-2021-24145 | WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload | modern events calendar lite | Attack Blocked by Atomicorp | 382238 |
| CVE-2021-24155 | WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload | backup guard | Detected by Atomicorp | 377360 |
| CVE-2022-3552 | BoxBilling<=4.22.1.5 - Remote Code Execution (RCE) | boxbilling | Attack Blocked by Atomicorp | 340128 , 380018 |
| CVE-2023-47873 | WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload | wp child theme generator | Detected by Atomicorp | 377360 |
| CVE-2025-5961 | WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload | migration, backup, staging | Detected by Atomicorp | 377360 |
| CVE-2026-13157 | Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload | Theme Demo Import | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-13158 | Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload | Everest Toolkit | Attack Blocked by Atomicorp | 351000 , 382238 , 390501 |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-7537 | MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Par | MDJM Event Management | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-56702 | Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload | adminer | Attack Blocked by Atomicorp | 351000 |
| CVE-2019-8394 | Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload | manageengine servicedesk plus | Detected by Atomicorp | 345493 |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2026-16548 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint | Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-45797 | HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload | heyform | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-42538 | IRIS has an Insecure File Upload | iris-web | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-11474 | Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload | student-management-system | Attack Blocked by Atomicorp | 351000 , 393655 |
| CVE-2026-18788 | Trippo ResponsiveFilemanager dialog.php unrestricted upload | ResponsiveFilemanager | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | icms2 | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-5573 | Technostrobe HI-LED-WR120-G2 fs unrestricted upload | hi-led-wr120-g2 firmware | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-78202 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload | Payroll System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-78245 | itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload | Online Pharmacy System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-85208 | itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload | Online Medicine Delivery System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86239 | liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload | FeehiCMS | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86305 | light0011 cms Upload.class.php upload unrestricted upload | cms | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-86666 | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload | iWebShop-5 | Attack Blocked by Atomicorp | 351000 |
| CVE-2023-3187 | Teachers Record Management System 1.0 - File Upload Type Validation | teachers record management system | Detected by Atomicorp | 345493 |
| CVE-2026-36722 | bookcars v8.3 Arbitrary Code Execution Vulnerability | bookcars v8.3 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-55419 | Reachy Mini: Unrestricted Upload of File with Dangerous Type | reachy mini | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-78337 | Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG | Prospero Flow CRM | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-79670 | Ech0 before 4.4.3 Stored XSS via SVG Upload | Ech0 | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-81931 | Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting | Prospero Flow CRM | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-75331 | tamguo 1.5.3 Cross-Site Scripting Vulnerability | - | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2024-14046 | OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted upload | OpenBoxes | Attack Blocked by Atomicorp | 351000 |
| CVE-2025-13815 | moxi159753 Mogu Blog v2 pictures unrestricted upload | mogublog | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-10172 | Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted upload | Multi-Store Inventory Management System | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-10806 | mjperpinosa stumasy add_post.php unrestricted upload | stumasy | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-10807 | mjperpinosa stumasy change_profile_image.php unrestricted upload | stumasy | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-16451 | zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload | ZS-Admin | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19210 | SourceCodester Photo Share Website ajax.php save_upload unrestricted upload | Photo Share Website | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-77681 | CodeAstro Online Job Portal update-profile.php unrestricted upload | Online Job Portal | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-82679 | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload | diem | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-85186 | itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload | Online Medicine Delivery System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19383 | saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted upload | SaiAdmin | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-19839 | SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted upload | Simple Doctors Appointment System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-5576 | SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload | Record Management System | Attack Blocked by Atomicorp | 340156 , 341245 , 351000 , 390501 |
| CVE-2026-76995 | SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload | Simple Online Food Ordering System | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-82629 | jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload | jeewx-boot | Attack Blocked by Atomicorp | 351000 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 300006 | Active | disruptive (deny) |
| 300016 | Active | disruptive (deny) |
| 300018 | Active | disruptive (deny) |
| 300019 | Active | disruptive (deny) |
| 300029 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 331324 | Active | non-disruptive (pass) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337210 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340016 | Active | disruptive (deny) |
| 340017 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340035 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340128 | Active | disruptive (deny) |
| 340144 | Active | disruptive (deny) |
| 340145 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340156 | Active | disruptive (deny) |
| 340157 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 340748 | Active | disruptive (deny) |
| 341145 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344380 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 346019 | Retired | non-disruptive (not available) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 360147 | Active | disruptive (deny) |
| 360148 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380018 | Active | disruptive (deny) |
| 380026 | Active | disruptive (deny) |
| 380122 | Active | disruptive (deny) |
| 382238 | Active | disruptive (deny) |
| 390501 | Active | disruptive (deny) |
| 390572 | Active | disruptive (deny) |
| 390585 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 391740 | Active | disruptive (deny) |
| 391742 | Active | disruptive (deny) |
| 391743 | Active | disruptive (deny) |
| 391746 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 393781 | Active | disruptive (deny) |
| 398001 | Active | non-disruptive (pass) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims: