VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 131 of 216
  • CVE-2022-4273HigDec 3, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Human Resource Management System 1.0. This issue affects some unknown processing of the file /hrm/controller/employee.php of the component Content-Type Handler. The manipulation of the argument…

  • CVE-2022-2647HigAug 4, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-34120HigJul 27, 2022
    risk 0.48cvss 7.2epss 0.18

    Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.

  • CVE-2022-30945HigMay 17, 2022
    risk 0.48cvss 8.5epss 0.01

    Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

  • CVE-2021-42123HigNov 30, 2021
    risk 0.48cvss 7.3epss 0.01

    Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side…

  • CVE-2020-7847HigFeb 23, 2021
    risk 0.48cvss 7.4epss 0.01

    The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.

  • CVE-2020-25406HigNov 18, 2020
    risk 0.48cvss 7.3epss 0.01

    app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.

  • CVE-2020-24948HigSep 3, 2020
    risk 0.48cvss 7.2epss 0.13

    The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimate Zip file, allowing high privilege users to upload arbitrary files, such as PHP, leading to remote command execution.

  • CVE-2019-15843HigSep 18, 2019
    risk 0.48cvss 7.4epss 0.01

    A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition involving a man-in-the-middle attack may lead to partial data leakage or malicious file writing.

  • CVE-2017-18435HigAug 2, 2019
    risk 0.48cvss 7.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

  • CVE-2018-19422HigNov 21, 2018
    risk 0.48cvss 7.2epss 0.64

    /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

  • CVE-2016-10258MedApr 11, 2018
    risk 0.48cvss 6.8epss 0.05

    Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and…

  • CVE-2026-16137HigAug 17, 2026
    risk 0.47cvss 7.2epss 0.01

    In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service…

  • CVE-2026-66271HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.01

    Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

  • CVE-2026-66270HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

  • CVE-2026-18969HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to…

  • CVE-2026-18933HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no…

  • CVE-2026-54416HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last…

  • CVE-2026-18788HigAug 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been…

  • CVE-2026-13158HigAug 1, 2026
    risk 0.47cvss 7.2epss 0.00

    The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on…