VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 126 of 222
  • CVE-2025-53119HigAug 25, 2025
    risk 0.50cvss 7.5epss 0.12

    An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to the server.

  • CVE-2025-55743HigAug 21, 2025
    risk 0.50cvss 8.8epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the…

  • CVE-2025-7847HigJul 31, 2025
    risk 0.50cvss 8.8epss 0.01

    The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2.9.3 and 2.9.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2025-0928HigJul 8, 2025
    risk 0.50cvss 8.8epss 0.01

    In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. This enabled the distribution of poisoned…

  • CVE-2025-3455HigMay 9, 2025
    risk 0.50cvss 8.8epss 0.01

    The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'start_restore' function in all versions up to, and including, 2.2. This makes it possible for…

  • CVE-2025-3616HigApr 22, 2025
    risk 0.50cvss 8.8epss 0.03

    The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gspb_make_proxy_api_request() function in versions 11.4 to 11.4.5. This makes it possible for authenticated attackers,…

  • CVE-2025-32370HigApr 6, 2025
    risk 0.50cvss 7.2epss 0.02

    Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a…

  • CVE-2025-2008HigApr 1, 2025
    risk 0.50cvss 8.8epss 0.01

    The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the import_single_post_as_csv() function in all versions up to, and including, 7.19. This makes it possible for authenticated…

  • CVE-2025-0394HigJan 14, 2025
    risk 0.50cvss 8.8epss 0.01

    The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the gh_big_file_upload() function in all versions up to, and including, 3.7.3.5. This…

  • CVE-2024-53982HigDec 4, 2024
    risk 0.50cvss —epss 0.00

    ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Zoo-Project Echo example. The Echo example available by default in Zoo installs implements file caching, which can be controlled by user-given parameters. No…

  • CVE-2024-9849HigNov 16, 2024
    risk 0.50cvss 8.8epss 0.01

    The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_save_thumbnail_callback' function in all versions up to, and including, 4.8. This makes it possible…

  • CVE-2024-37179HigOct 8, 2024
    risk 0.50cvss 7.7epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.

  • CVE-2024-8232HigSep 10, 2024
    risk 0.50cvss 7.5epss 0.13

    SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

  • CVE-2024-4389HigAug 14, 2024
    risk 0.50cvss 8.8epss 0.01

    The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile function in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with…

  • CVE-2024-6823HigAug 13, 2024
    risk 0.50cvss 8.8epss 0.01

    The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in all versions up to, and including, 3.18. This makes it possible for authenticated attackers,…

  • CVE-2024-40645HigJul 31, 2024
    risk 0.50cvss 8.8epss 0.01

    FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The Rebranding feature has a check on the client banner image requiring it to be 650…

  • CVE-2024-40400HigJul 19, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2024-3242HigJul 18, 2024
    risk 0.50cvss 8.8epss 0.01

    The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versions up to, and including, 2.4.43. This makes it possible for authenticated…

  • CVE-2024-31411HigJul 17, 2024
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with dangerous type vulnerability in Apache StreamPipes. Such a dangerous type might be an executable file that may lead to a remote code execution (RCE). The unrestricted upload is only possible for authenticated and authorized users. This issue…

  • CVE-2024-6319HigJul 4, 2024
    risk 0.50cvss 8.8epss 0.01

    The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up to, and including, 2.3.10. This makes it possible for authenticated attackers, with contributor-level and above permissions,…