VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 115 of 216
  • CVE-2026-24010HigJan 22, 2026
    risk 0.52cvss 8.0epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile…

  • CVE-2025-68398CriDec 18, 2025
    risk 0.52cvss 9.1epss 0.01

    Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

  • CVE-2025-65027HigDec 3, 2025
    risk 0.52cvss 7.6epss 0.00

    RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple unrestricted file upload vulnerabilities that allow authenticated users to upload malicious SVG or HTML files. When these files…

  • CVE-2025-58996CriNov 6, 2025
    risk 0.52cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Helmut Wandl Advanced Settings advanced-settings allows Upload a Web Shell to a Web Server.This issue affects Advanced Settings: from n/a through <= 3.1.1.

  • CVE-2025-62618HigOct 31, 2025
    risk 0.52cvss 8.0epss 0.00

    ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other users when they open the file. Because ELOG includes usernames and password hashes in certain HTTP requests, an attacker can obtain the target's credentials and…

  • CVE-2025-36174HigAug 24, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Integrated Analytics System 1.0.0.0 through 1.0.30.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

  • CVE-2024-8019CriMar 20, 2025
    risk 0.52cvss 9.1epss 0.01

    In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted…

  • CVE-2024-40693HigJan 24, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to victim…

  • CVE-2024-25034HigJan 24, 2025
    risk 0.52cvss 8.0epss 0.00

    IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in the File Manager T1 process. Attackers can make use of this weakness and upload malicious executable files into the system that can be sent to victims for…

  • CVE-2024-13171HigJan 14, 2025
    risk 0.52cvss 7.8epss 0.18

    Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2025-22389HigJan 4, 2025
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. This allows the upload of potentially malicious file types, including .docm .html. When…

  • CVE-2024-40695HigDec 20, 2024
    risk 0.52cvss 8.0epss 0.00

    IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into…

  • CVE-2024-50625HigDec 9, 2024
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling…

  • CVE-2024-40691HigDec 3, 2024
    risk 0.52cvss 8.0epss 0.00

    IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, and it can be sent to…

  • CVE-2024-48093HigOct 30, 2024
    risk 0.52cvss 8.0epss 0.01

    Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

  • CVE-2024-47319HigOct 5, 2024
    risk 0.52cvss 8.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form bit-form.This issue affects Bit Form: from n/a through <= 2.13.10.

  • CVE-2024-38529CriJul 29, 2024
    risk 0.52cvss 9.0epss 0.01

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to upload a PHP file in the…

  • CVE-2024-36415CriJun 10, 2024
    risk 0.52cvss 9.1epss 0.01

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows for remote code execution. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-29848HigMay 31, 2024
    risk 0.52cvss 7.2epss 0.64

    An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

  • CVE-2024-3412CriMay 29, 2024
    risk 0.52cvss 9.1epss 0.01

    The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for…