VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,451)

page 161 of 223
  • CVE-2022-0263HigJan 18, 2022
    risk 0.44cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2021-24490MedSep 13, 2021
    risk 0.44cvss 6.8epss 0.01

    The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import Emails feature, allowing arbitrary files to be uploaded. Furthermore, the plugin is also lacking any CSRF check, allowing such issue to be exploited via a…

  • CVE-2021-29699MedJul 15, 2021
    risk 0.44cvss 6.8epss 0.01

    IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.

  • CVE-2020-4928MedJan 4, 2021
    risk 0.44cvss 6.7epss 0.00

    IBM Cloud Pak System 2.3 could allow a local privileged attacker to upload arbitrary files. By intercepting the request and modifying the file extention, the attacker could execute arbitrary code on the server. IBM X-Force ID: 191705.

  • CVE-2020-15189MedSep 18, 2020
    risk 0.44cvss 6.8epss 0.03

    SOY CMS 3.0.2 and earlier is affected by Remote Code Execution (RCE) using Unrestricted File Upload. Cross-Site Scripting(XSS) vulnerability that was used in CVE-2020-15183 can be used to increase impact by redirecting the administrator to access a specially crafted page. This…

  • CVE-2018-20926MedAug 1, 2019
    risk 0.44cvss 6.7epss 0.00

    cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).

  • CVE-2018-20925MedAug 1, 2019
    risk 0.44cvss 6.7epss 0.00

    cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).

  • CVE-2018-18565MedNov 20, 2018
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, CoaguChek XS Plus before 03.01.06, CoaguChek XS Pro before 03.01.06, cobas h 232…

  • CVE-2023-34854MedSep 14, 2026
    risk 0.43cvss 6.6epss 0.00

    HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

  • CVE-2026-0496MedJan 13, 2026
    risk 0.43cvss 6.6epss 0.00

    SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to upload any file (including script files) without proper file format validation. This has low impact on confidentiality, integrity and availability of the application.

  • CVE-2025-32744MedJul 21, 2025
    risk 0.43cvss 6.6epss 0.00

    Dell AppSync, version(s) 4.6.0.0, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2025-49329MedJun 6, 2025
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2.

  • CVE-2025-47550MedMay 7, 2025
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue affects Instantio: from n/a through <= 3.3.16.

  • CVE-2025-39538MedApr 16, 2025
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Mathieu Chartier WP-Advanced-Search wp-advanced-search allows Upload a Web Shell to a Web Server.This issue affects WP-Advanced-Search: from n/a through <= 3.3.9.4.

  • CVE-2025-31577MedMar 31, 2025
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in appointify Appointify appointify allows Upload a Web Shell to a Web Server.This issue affects Appointify: from n/a through <= 1.0.8.

  • CVE-2025-2819MedMar 26, 2025
    risk 0.43cvss 6.6epss 0.00

    There is a risk of unauthorized file uploads in GT-SoftControl and potential file overwrites due to insufficient validation in the file selection process. This could lead to data integrity issues and unauthorized access by an authenticated privileged user.

  • CVE-2025-1025HigFeb 5, 2025
    risk 0.43cvss 7.5epss 0.19

    Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.

  • CVE-2024-56264MedJan 2, 2025
    risk 0.43cvss 6.6epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Selector: from n/a through <= 1.14.0.

  • CVE-2024-53811MedDec 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit wdesignkit allows Upload a Web Shell to a Web Server.This issue affects WDesignkit: from n/a through <= 1.0.40.

  • CVE-2024-49676MedOct 23, 2024
    risk 0.43cvss 6.6epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-for-elementor allows Upload a Web Shell to a Web Server.This issue affects Custom Icons for Elementor: from n/a through <= 0.3.3.