VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 117 of 216
  • CVE-2020-5256HigMar 9, 2020
    risk 0.52cvss 7.9epss 0.02

    BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where…

  • CVE-2018-3758HigJun 7, 2018
    risk 0.52cvss 8.8epss 0.27

    Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

  • CVE-2018-11494HigMay 26, 2018
    risk 0.52cvss 8.0epss 0.02

    The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows attackers to execute arbitrary code if the remove step is skipped, because the attacker can discover a secret temporary directory…

  • CVE-2017-17593HigDec 13, 2017
    risk 0.52cvss 7.5epss 0.06

    Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.

  • CVE-2016-1713HigApr 14, 2017
    risk 0.52cvss 7.3epss 0.17

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an…

  • CVE-2017-6104HigMar 2, 2017
    risk 0.52cvss 7.5epss 0.07

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

  • CVE-2026-40487HigApr 18, 2026
    risk 0.51cvss 8.9epss 0.00

    Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then…

  • CVE-2025-13065HigDec 6, 2025
    risk 0.51cvss 8.8epss 0.13

    The Starter Templates plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 4.4.41. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a…

  • CVE-2025-55912HigSep 18, 2025
    risk 0.51cvss 7.3epss 0.02

    An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

  • CVE-2024-47423HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which can be…

  • CVE-2024-45137HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file which, when executed,…

  • CVE-2024-45136HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious file which can then be…

  • CVE-2024-44871HigSep 10, 2024
    risk 0.51cvss 7.2epss 0.16

    An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-7987HigAug 26, 2024
    risk 0.51cvss 7.8epss 0.00

    A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a…

  • CVE-2024-3483HigMay 15, 2024
    risk 0.51cvss 7.8epss 0.01

    Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

  • CVE-2024-23762HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Unrestricted File Upload vulnerability in Content Manager feature in Gambio 4.9.2.0 allows attackers to execute arbitrary code via upload of crafted PHP file.

  • CVE-2023-25365HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

  • CVE-2023-41725HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

  • CVE-2023-45555HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.01

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via a crafted file to the down_url function in zzz.php file.

  • CVE-2023-44824HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.