VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 17 of 216
  • CVE-2019-12409CriNov 18, 2019
    risk 0.65cvss 9.8epss 0.22

    The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring…

  • CVE-2015-9499CriOct 22, 2019
    risk 0.65cvss 9.8epss 0.16

    The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

  • CVE-2019-10959CriJun 13, 2019
    risk 0.65cvss 10.0epss 0.03

    BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS,…

  • CVE-2019-7838CriJun 12, 2019
    risk 0.65cvss 9.8epss 0.17

    ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2018-18475CriOct 23, 2018
    risk 0.65cvss 9.8epss 0.20

    Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

  • CVE-2018-16287CriSep 14, 2018
    risk 0.65cvss 9.8epss 0.20

    LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

  • CVE-2018-11091CriMay 14, 2018
    risk 0.65cvss 9.9epss 0.04

    An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system commands. This vulnerability occurs because an attacker is able to adjust the…

  • CVE-2018-10942CriMay 10, 2018
    risk 0.65cvss 9.8epss 0.13

    modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

  • CVE-2017-18048HigJan 23, 2018
    risk 0.65cvss 8.8epss 0.63

    Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.

  • CVE-2017-9080HigMay 19, 2017
    risk 0.65cvss 8.8epss 0.62

    PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.

  • CVE-2026-32463CriAug 18, 2026
    risk 0.64cvss 9.9epss

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

  • CVE-2026-15748CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist…

  • CVE-2026-50768CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function.

  • CVE-2026-16098CriAug 16, 2026
    risk 0.64cvss 9.8epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which…

  • CVE-2026-18391CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a…

  • CVE-2026-15039CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.

  • CVE-2026-72592CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on the server. The application ships with an empty upload extension filter ( = array) and no authentication enabled by default…

  • CVE-2026-19089CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.00

    The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files…

  • CVE-2022-4995CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.01

    Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js…

  • CVE-2026-70558CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard…