VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 156 of 216
  • CVE-2025-20375MedNov 5, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this…

  • CVE-2025-61181MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.00

    daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.

  • CVE-2025-52078MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.

  • CVE-2025-54962MedAug 4, 2025
    risk 0.42cvss 6.4epss 0.00

    /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI.

  • CVE-2025-54757MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    Multiple versions of PowerCMS allow unrestricted upload of dangerous files. If a product administrator accesses a malicious file uploaded by a product user, an arbitrary script may be executed on the browser.

  • CVE-2025-1725MedJun 3, 2025
    risk 0.42cvss 6.4epss 0.00

    The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output…

  • CVE-2025-3444MedMay 22, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

  • CVE-2024-9544MedMay 22, 2025
    risk 0.42cvss 6.4epss 0.00

    The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 8.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…

  • CVE-2025-28168MedMay 5, 2025
    risk 0.42cvss 6.4epss 0.00

    The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass…

  • CVE-2025-32215MedApr 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue affects Accessibility Suite: from n/a through <= 4.18.

  • CVE-2025-0731MedFeb 26, 2025
    risk 0.42cvss 6.5epss 0.01

    An unauthenticated remote attacker can upload a .aspx file instead of a PV system picture through the demo account. The code can only be executed in the security context of the user.

  • CVE-2024-13333HigJan 17, 2025
    risk 0.42cvss 7.5epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2024-41454MedJan 15, 2025
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

  • CVE-2023-42248MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".

  • CVE-2024-11391HigDec 3, 2024
    risk 0.42cvss 7.5epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with…

  • CVE-2024-8066HigNov 28, 2024
    risk 0.42cvss 7.5epss 0.01

    The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2024-7985HigOct 29, 2024
    risk 0.42cvss 7.5epss 0.02

    The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it possible for…

  • CVE-2024-8126HigSep 26, 2024
    risk 0.42cvss 7.5epss 0.01

    The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted…

  • CVE-2024-7384HigAug 22, 2024
    risk 0.42cvss 7.5epss 0.01

    The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2. This…

  • CVE-2024-5226MedAug 8, 2024
    risk 0.42cvss 6.4epss 0.00

    The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and including, 5.4.10 due to insufficient validation of SVG files. This makes it possible for authenticated attackers, with…