#CWE-434
All CosmicBytez Labs articles tagged #CWE-434, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-82901: Ultra Addons for Contact Form 7 Arbitrary File Upload
Ultra Addons for Contact Form 7 (≤ 3.5.50) allows unauthenticated arbitrary file upload via a weakly validated PDF Generator signature field, enabling RCE.
- Security
CVE-2026-16286: Unauthenticated Web Shell Upload in TRtek Software Repository Management
Unrestricted file upload flaw lets attackers plant a web shell on TRtek's Software Repository Management with no authentication required.
- Security
CVE-2021-47933: WordPress MStore API 2.0.6 Arbitrary File
MStore API 2.0.6 for WordPress allows unauthenticated attackers to upload arbitrary PHP files via the REST API config_file endpoint, achieving remote code...
- Security
CVE-2021-47936: OpenCATS 0.9.4 Unauthenticated RCE via PHP
OpenCATS 0.9.4 allows unauthenticated attackers to upload malicious PHP files through the careers job application endpoint, achieving remote code...
- Security
CVE-2016-20052: Snews CMS 1.7 Unrestricted File Upload
Snews CMS 1.7 contains a critical unrestricted file upload vulnerability allowing unauthenticated attackers to upload PHP webshells to the snews_files...