VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,451)

page 169 of 223
  • CVE-2026-10806MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely.…

  • CVE-2026-10205MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in Metasoft 美特软件 MetaCRM 6.4.0. The impacted element is an unknown function of the file develop/systparam/softlogo/upload.jsp. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has…

  • CVE-2026-10172MedMay 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module…

  • CVE-2026-42879MedMay 27, 2026
    risk 0.41cvss 6.3epss 0.00

    FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' product image upload functionality. An attacker with valid credentials can upload a PHP file disguised as…

  • CVE-2026-9445MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the…

  • CVE-2026-9374MedMay 24, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a manipulation results in unrestricted upload. The attack is possible to be carried…

  • CVE-2025-65416MedMay 11, 2026
    risk 0.41cvss 6.3epss 0.00

    docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.

  • CVE-2025-67886MedMay 8, 2026
    risk 0.41cvss 6.3epss 0.01

    Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for…

  • CVE-2026-7732MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.

  • CVE-2026-7696MedMay 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. This impacts an unknown function of the file /SubstationWEBV2/main/uploadH5Files. The manipulation of the argument File results in unrestricted upload. The attack…

  • CVE-2026-7107MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-7044MedApr 26, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This…

  • CVE-2026-7043MedApr 26, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2026-6489MedApr 17, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects some unknown processing of the file admin/addteacher.php of the component Background Management Page. The manipulation of the argument image results in…

  • CVE-2026-5670MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipulation of the argument File results in…

  • CVE-2026-5546MedApr 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2026-5472MedApr 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument…

  • CVE-2026-5181MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_category. Such manipulation of the argument img leads to unrestricted upload. The…

  • CVE-2026-4586MedMar 23, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web/api/controller/driver/JdbcDriverController.java of the component JDBC Driver…

  • CVE-2026-4505MedMar 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted…