VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 18 of 222
  • CVE-2026-8778CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This…

  • CVE-2026-71805CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload.

  • CVE-2026-50894CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

  • CVE-2026-44402CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers…

  • CVE-2025-9314CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

  • CVE-2026-84637CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading…

  • CVE-2026-14494CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form…

  • CVE-2026-75327CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:

  • CVE-2025-61165CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.

  • CVE-2026-80235CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2026-16286CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository…

  • CVE-2026-32559CriAug 24, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

  • CVE-2026-74018CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

  • CVE-2026-74016CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

  • CVE-2026-74014CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

  • CVE-2026-73373CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

  • CVE-2026-73996CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

  • CVE-2026-66627CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

  • CVE-2026-32474CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

  • CVE-2026-32463CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.