On this page

CWE-434: Unrestricted Upload of File with Dangerous Type

Weakness Summary

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

  • Canonical source: MITRE CWE-434 (opens in a new tab)
  • Published Atomicorp CVE observations: 144
  • Distinct affected products in those observations: 133
  • Active Atomicorp rules associated with this weakness: 76

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2024-56064WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEindeed-wp-superbackupAttack Blocked by Atomicorp382238
CVE-2025-34040Zhiyuan OA - arbitrary file upload leadingZhiyuan OA Web Application SystemAttack Blocked by Atomicorp330791 , 340007 , 340152
CVE-2025-34163Dongsheng Logistics Software Unauthenticated Arbitrary File UploadDongsheng Logistics SoftwareAttack Blocked by Atomicorp351000
CVE-2025-47577TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Uploadti-woocommerce-wishlistAttack Blocked by Atomicorp382238
CVE-2026-57827Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12rsfiles!Attack Blocked by Atomicorp351000
CVE-2019-4013IBM Bigfix Platform 9.5.9.62 - Arbitrary File Uploadbigfix platformAttack Blocked by Atomicorp392301
CVE-2014-8739WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File Uploadcreative contact formAttack Blocked by Atomicorp300016
CVE-2015-10138Work The Flow File Upload <= 2.5.2 - Arbitrary File Uploadwork the flow file uploadAttack Blocked by Atomicorp351000
CVE-2015-4455WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Uploadaviary image editor add-on for gravity formsAttack Blocked by Atomicorp340007 , 391742 , 391743
CVE-2015-9499WordPress ShowBiz Pro <= 1.7.1 - Authenticated Arbitrary File Upload to RCEshowbiz proAttack Blocked by Atomicorp300019 , 300029
CVE-2016-15042WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Uploadfrontend file managerAttack Blocked by Atomicorp382238
CVE-2016-15043WP Mobile Detector <= 3.5 - Unrestricted File Uploadwp mobile detectorAttack Blocked by Atomicorp340162 , 340163 , 391740
CVE-2016-3088Apache ActiveMQ Fileserver - Arbitrary File WriteactivemqAttack Blocked by Atomicorp392301
CVE-2017-16949Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Uploadanonymous post proDetected by Atomicorp345493
CVE-2017-17976PerfexCRM 1.9.7 - Arbitrary File Uploadperfex crmAttack Blocked by Atomicorp392301
CVE-2018-17440D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanagerAttack Blocked by Atomicorp340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2018-20526Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversalroxy filemanAttack Blocked by Atomicorp330791 , 340152
CVE-2019-10647ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)zzzphpAttack Blocked by Atomicorp340162 , 340163
CVE-2020-12800WordPress Contact Form 7 <1.3.3.3 - Remote Code Executiondrag and drop multiple file upload - contact form 7Attack Blocked by Atomicorp300018
CVE-2020-25213WordPress File Manager Plugin - Remote Code Executionfile managerAttack Blocked by Atomicorp393781
CVE-2021-23394elFinder < 2.1.58 - Remote Code ExecutionelfinderAttack Blocked by Atomicorp393781
CVE-2021-24212WooCommerce Help Scout - Arbitrary File Uploadhelp scoutAttack Blocked by Atomicorp330791 , 340152 , 382238
CVE-2021-24284WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File UploadkaswaraAttack Blocked by Atomicorp382238
CVE-2021-24499WordPress Workreap - Remote Code ExecutionworkreapAttack Blocked by Atomicorp330791 , 340152 , 382238
CVE-2021-25003WordPress WPCargo Track & Trace <6.9.0 - Remote Code Executionwpcargo track &amp; traceDetected by Atomicorp331324
CVE-2021-30118Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code ExecutionvsaAttack Blocked by Atomicorp344365 , 392301
CVE-2021-3378FortiLogger 4.4.2.2 - Arbitrary File UploadfortiloggerAttack Blocked by Atomicorp330791 , 340152
CVE-2021-34624WordPress ProfilePress 3.0-3.1.3 - Arbitrary File UploadprofilepressAttack Blocked by Atomicorp382238
CVE-2021-43421Studio-42 elFinder <2.1.60 - Arbitrary File UploadelfinderAttack Blocked by Atomicorp393781
CVE-2021-4449ZoomSounds Plugin - Unauthenticated Arbitrary File UploadzoomsoundsAttack Blocked by Atomicorp392301
CVE-2022-1952WordPress eaSYNC Booking <1.1.16 - Arbitrary File Uploadfree booking plugin for hotels, restaurant and car rentalAttack Blocked by Atomicorp382238
CVE-2022-34128GLPI Cartography Plugin v6.0.0 - Unauthenticated Remote Code Execution (RCE)positionsAttack Blocked by Atomicorp392301
CVE-2022-47615LearnPress Plugin < 4.2.0 - Local File InclusionlearnpressAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2023-2648Weaver E-Office 9.5 - Remote Code Executione-officeAttack Blocked by Atomicorp330791 , 340152
CVE-2023-3722Avaya Aura Device Services - OS Command Injectionaura device servicesAttack Blocked by Atomicorp392301
CVE-2023-37629Online Piggery Management System v1.0 - Unauthenticated File Uploadsimple online piggery management systemAttack Blocked by Atomicorp330791
CVE-2023-4596WordPress Plugin Forminator 1.24.6 - Arbitrary File UploadforminatorAttack Blocked by Atomicorp300006
CVE-2023-51409Jordy Meow AI Engine - Unrestricted File Uploadai engineAttack Blocked by Atomicorp382238
CVE-2023-5360WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Uploadroyal elementor addonsAttack Blocked by Atomicorp382238
CVE-2024-2667InstaWP Connect <= 0.1.0.22 - Unauthenticated Arbitrary File Uploadinstawp connectAttack Blocked by Atomicorp340162 , 340163
CVE-2024-50623Cleo Harmony < 5.8.0.21 - Arbitary File ReadharmonyAttack Blocked by Atomicorp344365
CVE-2024-8425WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Uploadwoocommerce ultimate gift cardAttack Blocked by Atomicorp382238
CVE-2025-26319FlowiseAI Flowise <= 2.2.6 - Arbitrary File UploadflowiseAttack Blocked by Atomicorp346019
CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader - DeserializationnetweaverAttack Blocked by Atomicorp330791 , 340152
CVE-2025-6058WPBookit <= 1.0.4 - Unauthenticated Arbitrary File UploadwpbookitAttack Blocked by Atomicorp382238
CVE-2025-9314Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File UploadThe Developer Tools WordPress plugin through 1.1.3Attack Blocked by Atomicorp351000
CVE-2026-0740Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Uploadninja forms file uploadsAttack Blocked by Atomicorp382238
CVE-2026-14894WordPress Super Forms <= 6.3.313 - Arbitrary File Uploadsuper-formsAttack Blocked by Atomicorp340748
CVE-2026-36669ck_upload_handler.php in Feng Office 3.11.13.11 Arbitrary File Upload Vulnerabilityck upload handler.php in Feng Office 3.11.13.11Attack Blocked by Atomicorp351000
CVE-2026-49827WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)WebErpMesv2Attack Blocked by Atomicorp351000
CVE-2026-50894easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability-Attack Blocked by Atomicorp351000
CVE-2026-67678RainyGao-Hithub DocSys v.2.02.80 Arbitrary Code Execution VulnerabilityRainyGao-Hithub DocSys v.2.02.80Attack Blocked by Atomicorp351000
CVE-2026-67688ICS-Park Smart Park Management System v2.0 Arbitrary Code Execution VulnerabilityICS-Park Smart Park Management System v2.0Attack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-71805Path Traversal-Attack Blocked by Atomicorp351000
CVE-2026-72592dulldusk phpfm - Unauthenticated Remote Code Execution via Unrestricted PHP File UploadphpfmAttack Blocked by Atomicorp340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75327In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java Arbitrary File Upload VulnerabilityIn DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.javaAttack Blocked by Atomicorp351000
CVE-2026-53649Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEjoroAttack Blocked by Atomicorp340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-11419Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Writeon-prem enterprise serverAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2016-20052Snews CMS 1.7 Unrestricted File Upload via snews_filessnewsAttack Blocked by Atomicorp351000
CVE-2018-25114osCommerce 2.3.4.1 - Remote Code ExecutionOnline MerchantAttack Blocked by Atomicorp340023 , 340095 , 344360 , 344370
CVE-2022-4995Weaver E-cology 9.0 File Upload RCE via uploaderOperate.jspE-cology 9.0Attack Blocked by Atomicorp351000
CVE-2024-58348WordPress Background Image Cropper 1.2 Remote Code ExecutionBackground Image CropperAttack Blocked by Atomicorp340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgiSNMP Web ProAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-70558Dinky Unauthenticated Arbitrary File Write via /download/uploadFromRsByLocal Gated Only by Hardcoded Default TokenDinkyAttack Blocked by Atomicorp351000
CVE-2023-7305SmartBI RMIServlet Unrestricted File Upload RCESmartBIAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2021-21351XStream <1.4.16 - Remote Code ExecutionxstreamAttack Blocked by Atomicorp344380
CVE-2026-49849xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code ExecutionxshopAttack Blocked by Atomicorp351000
CVE-2026-32475Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerElementor ProDetected by Atomicorp398001
CVE-2017-6090PhpColl 2.5.1 Arbitrary File UploadphpcollabAttack Blocked by Atomicorp391746
CVE-2018-17442D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilitiescentral wifimanagerAttack Blocked by Atomicorp340147 , 340148 , 341256 , 342259 , 346755 , 350148 , 390585
CVE-2019-15813Sentrifugo 3.2 - File Upload Restriction BypasssentrifugoDetected by Atomicorp345493
CVE-2019-9189Prima Access Control 2.3.35 - Arbitrary File UploadflexairAttack Blocked by Atomicorp342259 , 344360 , 344363 , 344364 , 344366 , 350147 , 390724 , 390726 , 392647
CVE-2020-8639TestLink 1.9.20 - Unrestricted File Upload (Authenticated)testlinkDetected by Atomicorp345493
CVE-2022-1329Elementor Website Builder - Remote Code Executionwebsite builderDetected by Atomicorp377360
CVE-2023-48777WordPress Elementor 3.18.1 - File Upload/Remote Code Executionwebsite builderDetected by Atomicorp377360
CVE-2025-59710biztalk360 Arbitrary Code Execution Vulnerabilitybiztalk360Attack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-70151scholars tracking system Arbitrary Code Execution Vulnerabilityscholars tracking systemAttack Blocked by Atomicorp351000
CVE-2026-55676Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload componentMalcolmAttack Blocked by Atomicorp351000
CVE-2026-72557Cockpit CMS Cockpit CMS - Unrestricted File UploadCockpit CMSAttack Blocked by Atomicorp351000
CVE-2018-25409SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.phpSIM-PKHAttack Blocked by Atomicorp351000
CVE-2019-25673UniSharp Laravel File Manager v2.0.0-alpha7 Arbitrary File UploadLaravel File ManagerAttack Blocked by Atomicorp351000
CVE-2021-47943TextPattern CMS 4.8.7 Remote Code Execution via File UploadTextPattern CMSAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-34735Hytale Modding Vulnerable to Remote Code Execution via File Upload Bypass in FileControllerwikiAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-67206Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File UploadwolfcmsAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary FallbackwekanAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-26212Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCERara One Click Demo ImportAttack Blocked by Atomicorp351000
CVE-2026-39931OpenEMR Authenticated SQL Injection via backup.php Import FeatureopenemrAttack Blocked by Atomicorp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63429HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextheyformAttack Blocked by Atomicorp351000
CVE-2026-82524UnoPim File Upload RCE via TinyMCE Image Upload EndpointunopimAttack Blocked by Atomicorp351000
CVE-2024-24809Traccar - Unrestricted File UploadtraccarAttack Blocked by Atomicorp330791 , 340152 , 391213
CVE-2026-65986CVAT has stored XSS via annotation guide assetscvatAttack Blocked by Atomicorp333140 , 333141 , 340095 , 341256 , 342259 , 350147 , 350148
CVE-2017-12615Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcatAttack Blocked by Atomicorp337209 , 337210 , 337211 , 340095 , 340128 , 344360 , 345493 , 347009 , 380018 , 380026 , 390904 , 392301
CVE-2017-12617Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)tomcatAttack Blocked by Atomicorp345493 , 392301
CVE-2026-5718Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Executiondrag-and-drop-multiple-file-upload-contact-form-7Attack Blocked by Atomicorp382238
CVE-2026-53599Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mocoreAttack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2020-20969PluckCMS 4.7.10 - Unrestricted File UploadpluckAttack Blocked by Atomicorp340035 , 390727 , 392301 , 392648
CVE-2021-24145WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Uploadmodern events calendar liteAttack Blocked by Atomicorp382238
CVE-2021-24155WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Uploadbackup guardDetected by Atomicorp377360
CVE-2022-3552BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)boxbillingAttack Blocked by Atomicorp340128 , 380018
CVE-2023-47873WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Uploadwp child theme generatorDetected by Atomicorp377360
CVE-2025-5961WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Uploadmigration, backup, stagingDetected by Atomicorp377360
CVE-2026-13157Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File UploadTheme Demo ImportAttack Blocked by Atomicorp351000
CVE-2026-13158Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File UploadEverest ToolkitAttack Blocked by Atomicorp351000 , 382238 , 390501
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload MechanismfacturascriptsAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp liteAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2026-7537MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' ParMDJM Event ManagementAttack Blocked by Atomicorp351000
CVE-2026-56702Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUploadadminerAttack Blocked by Atomicorp351000
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Uploadmanageengine servicedesk plusDetected by Atomicorp345493
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector mapsAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2026-16548Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response EndpointChat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and ChatAttack Blocked by Atomicorp351000
CVE-2026-45797HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadheyformAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-42538IRIS has an Insecure File Uploadiris-webAttack Blocked by Atomicorp351000
CVE-2026-11474Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted uploadstudent-management-systemAttack Blocked by Atomicorp351000 , 393655
CVE-2026-18788Trippo ResponsiveFilemanager dialog.php unrestricted uploadResponsiveFilemanagerAttack Blocked by Atomicorp351000
CVE-2026-54611InstantCMS has Remote Code Execution in package installericms2Attack Blocked by Atomicorp340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-5573Technostrobe HI-LED-WR120-G2 fs unrestricted uploadhi-led-wr120-g2 firmwareAttack Blocked by Atomicorp351000
CVE-2026-78202itsourcecode Payroll System admin_class.php save_settings unrestricted uploadPayroll SystemAttack Blocked by Atomicorp351000
CVE-2026-78245itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted uploadOnline Pharmacy SystemAttack Blocked by Atomicorp351000
CVE-2026-85208itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted uploadOnline Medicine Delivery SystemAttack Blocked by Atomicorp351000
CVE-2026-86239liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted uploadFeehiCMSAttack Blocked by Atomicorp351000
CVE-2026-86305light0011 cms Upload.class.php upload unrestricted uploadcmsAttack Blocked by Atomicorp351000
CVE-2026-86666aircheng-org iWebShop-5 pic.php uploadFile unrestricted uploadiWebShop-5Attack Blocked by Atomicorp351000
CVE-2023-3187Teachers Record Management System 1.0 - File Upload Type Validationteachers record management systemDetected by Atomicorp345493
CVE-2026-36722bookcars v8.3 Arbitrary Code Execution Vulnerabilitybookcars v8.3Attack Blocked by Atomicorp351000
CVE-2026-55419Reachy Mini: Unrestricted Upload of File with Dangerous Typereachy miniAttack Blocked by Atomicorp351000
CVE-2026-78337Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVGProspero Flow CRMAttack Blocked by Atomicorp351000
CVE-2026-79670Ech0 before 4.4.3 Stored XSS via SVG UploadEch0Attack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-81931Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scriptingProspero Flow CRMAttack Blocked by Atomicorp351000
CVE-2026-75331tamguo 1.5.3 Cross-Site Scripting Vulnerability-Attack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2024-14046OpenBoxes Document Upload Controller DocumentController.groovy DocumentController unrestricted uploadOpenBoxesAttack Blocked by Atomicorp351000
CVE-2025-13815moxi159753 Mogu Blog v2 pictures unrestricted uploadmogublogAttack Blocked by Atomicorp351000
CVE-2026-10172Bdtask Multi-Store Inventory Management System Component Module.php upload unrestricted uploadMulti-Store Inventory Management SystemAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-10806mjperpinosa stumasy add_post.php unrestricted uploadstumasyAttack Blocked by Atomicorp351000
CVE-2026-10807mjperpinosa stumasy change_profile_image.php unrestricted uploadstumasyAttack Blocked by Atomicorp351000
CVE-2026-16451zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted uploadZS-AdminAttack Blocked by Atomicorp351000
CVE-2026-19210SourceCodester Photo Share Website ajax.php save_upload unrestricted uploadPhoto Share WebsiteAttack Blocked by Atomicorp351000
CVE-2026-77681CodeAstro Online Job Portal update-profile.php unrestricted uploadOnline Job PortalAttack Blocked by Atomicorp351000
CVE-2026-82679diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted uploaddiemAttack Blocked by Atomicorp351000
CVE-2026-85186itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted uploadOnline Medicine Delivery SystemAttack Blocked by Atomicorp351000
CVE-2026-19383saithink/saigroup SaiAdmin Plugin Upload Endpoint upload shell_exec unrestricted uploadSaiAdminAttack Blocked by Atomicorp351000
CVE-2026-19839SourceCodester Simple Doctors Appointment System save_file.php save_doctor unrestricted uploadSimple Doctors Appointment SystemAttack Blocked by Atomicorp351000
CVE-2026-5576SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted uploadRecord Management SystemAttack Blocked by Atomicorp340156 , 341245 , 351000 , 390501
CVE-2026-76995SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted uploadSimple Online Food Ordering SystemAttack Blocked by Atomicorp351000
CVE-2026-82629jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted uploadjeewx-bootAttack Blocked by Atomicorp351000

Associated Atomicorp WAF Rules

RuleStatusBehavior
300006Activedisruptive (deny)
300016Activedisruptive (deny)
300018Activedisruptive (deny)
300019Activedisruptive (deny)
300029Activedisruptive (deny)
330791Activedisruptive (deny)
331324Activenon-disruptive (pass)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
337209Activedisruptive (deny)
337210Activedisruptive (deny)
337211Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340016Activedisruptive (deny)
340017Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340035Activedisruptive (deny)
340095Activedisruptive (deny)
340128Activedisruptive (deny)
340144Activedisruptive (deny)
340145Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340152Activedisruptive (deny)
340156Activedisruptive (deny)
340157Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340193Activedisruptive (deny)
340748Activedisruptive (deny)
341145Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344380Activedisruptive (deny)
345493Activenon-disruptive (pass)
346019Retirednon-disruptive (not available)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
351000Activedisruptive (deny)
360147Activedisruptive (deny)
360148Activedisruptive (deny)
377360Activenon-disruptive (pass)
380018Activedisruptive (deny)
380026Activedisruptive (deny)
380122Activedisruptive (deny)
382238Activedisruptive (deny)
390501Activedisruptive (deny)
390572Activedisruptive (deny)
390585Activedisruptive (deny)
390709Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
390904Activedisruptive (deny)
391213Activedisruptive (deny)
391740Activedisruptive (deny)
391742Activedisruptive (deny)
391743Activedisruptive (deny)
391746Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
393781Activedisruptive (deny)
398001Activenon-disruptive (pass)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-1 (opens in a new tab)