VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 125 of 216
  • CVE-2025-12048HigNov 12, 2025
    risk 0.49cvss 7.5epss 0.00

    An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessment that could allow remote code execution or unauthorized control of the affected system.

  • CVE-2025-60735HigOct 24, 2025
    risk 0.49cvss 7.6epss 0.00

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function

  • CVE-2025-60731HigOct 24, 2025
    risk 0.49cvss 7.6epss 0.00

    PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function

  • CVE-2025-9212HigOct 3, 2025
    risk 0.49cvss 7.5epss 0.00

    The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with…

  • CVE-2025-59835HigOct 2, 2025
    risk 0.49cvss epss 0.00

    LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attackers can exploit the /api/v1/files/documents interface to perform arbitrary file uploads. Since this interface does not strictly restrict the storage directory…

  • CVE-2025-10009HigSep 22, 2025
    risk 0.49cvss epss 0.00

    Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files.

  • CVE-2025-45586HigSep 12, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a crafted PUT request.

  • CVE-2025-6207HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with…

  • CVE-2025-5061HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with…

  • CVE-2025-47187HigJul 23, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to perform a file upload attack due to…

  • CVE-2025-7438HigJul 18, 2025
    risk 0.49cvss 7.5epss 0.01

    The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with…

  • CVE-2025-6206HigJun 24, 2025
    risk 0.49cvss 7.5epss 0.00

    The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aiomatic_image_editor_ajax_submit' function in all versions up to, and…

  • CVE-2024-55926HigJan 23, 2025
    risk 0.49cvss 7.6epss 0.00

    A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation of headers, attackers can gain unauthorized access to data

  • CVE-2025-0472HigJan 16, 2025
    risk 0.49cvss 7.5epss 0.01

    Information exposure in the PMB platform affecting versions 4.2.13 and earlier. This vulnerability allows an attacker to upload a file to the environment and enumerate the internal files of a machine by looking at the request response.

  • CVE-2024-8746HigOct 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for…

  • CVE-2024-22641HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.01

    TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

  • CVE-2024-30533HigMar 31, 2024
    risk 0.49cvss 7.5epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layouts for Elementor: from n/a before 1.8.

  • CVE-2024-28425HigMar 14, 2024
    risk 0.49cvss 7.5epss 0.01

    greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-6562HigDec 20, 2023
    risk 0.49cvss 7.5epss 0.01

    JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.

  • CVE-2023-39539HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.