VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 165 of 216
  • CVE-2025-9847MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-9841MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out…

  • CVE-2025-9800MedSep 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. Affected by this issue is the function Import of the file apps/sim/app/api/files/upload/route.ts of the component HTML File Parser. Executing manipulation of the argument File can…

  • CVE-2025-9795MedSep 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible…

  • CVE-2025-9415MedAug 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is…

  • CVE-2025-9406MedAug 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function uploadImage of the file CmsArticleController.java of the component com.mossle.cms.web.CmsArticleController.uploadImage. This manipulation of the argument Upload causes unrestricted upload.…

  • CVE-2025-9400MedAug 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload of the file app/utils/base/plugin/P_file.php. This manipulation of the argument File causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-9397MedAug 24, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of the file /system/traits/media.php. Executing manipulation of the argument files[] can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made…

  • CVE-2025-27714MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise.

  • CVE-2025-24489MedAug 21, 2025
    risk 0.41cvss 6.3epss 0.00

    An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise.

  • CVE-2025-9153MedAug 19, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument photo results in unrestricted upload. The attack can be launched…

  • CVE-2025-9099MedAug 18, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Acrel Environmental Monitoring Cloud Platform up to 20250804. This affects an unknown part of the file /NewsManage/UploadNewsImg. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely.…

  • CVE-2025-8965MedAug 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the…

  • CVE-2025-8859MedAug 11, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched…

  • CVE-2025-8841MedAug 11, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload.…

  • CVE-2025-8775MedAug 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function execute of the file /api/code/upload of the component Scheduled Task Handler. The manipulation of the argument File leads to…

  • CVE-2025-8764MedAug 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-8526MedAug 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/UploadController.java. The manipulation of the argument…

  • CVE-2025-8504MedAug 3, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unknown part of the file /userregistration.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2025-8344MedJul 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in openviglet shio up to 0.3.8. Affected is the function shStaticFileUpload of the file shio-app/src/main/java/com/viglet/shio/api/staticfile/ShStaticFileAPI.java. The manipulation of the argument filename leads to…