VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 187 of 217
  • CVE-2023-20040MedJan 20, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a…

  • CVE-2022-43283MedOct 28, 2022
    risk 0.36cvss 5.5epss 0.00

    wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.

  • CVE-2021-21350MedMar 23, 2021
    risk 0.36cvss 5.3epss 0.15

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the…

  • CVE-2020-15649MedAug 10, 2020
    risk 0.36cvss 5.5epss 0.01

    Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This…

  • CVE-2020-9320MedFeb 20, 2020
    risk 0.36cvss 5.5epss 0.03

    Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security…

  • CVE-2018-15333MedDec 28, 2018
    risk 0.36cvss 5.5epss 0.00

    On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snapshot files on the BIG-IP configuration utility such as QKView and TCPDumps.

  • CVE-2018-1552MedNov 2, 2018
    risk 0.36cvss 5.5epss 0.02

    IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to…

  • CVE-2016-0354MedAug 29, 2017
    risk 0.36cvss 5.5epss 0.01

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.

  • CVE-2026-58428MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

  • CVE-2026-39527MedJun 15, 2026
    risk 0.35cvss 5.4epss 0.00

    Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

  • CVE-2026-36722MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2026-34031MedJun 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could…

  • CVE-2026-33582MedJun 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to…

  • CVE-2026-24034MedJan 22, 2026
    risk 0.35cvss 5.4epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.

  • CVE-2021-47783MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks…

  • CVE-2023-53876MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and…

  • CVE-2025-61681MedOct 3, 2025
    risk 0.35cvss 5.4epss 0.00

    KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its file upload functionality that can be exploited for stored XSS. The upload endpoint only validates file types based on Content-Type headers, lacks file content…

  • CVE-2025-10000MedSep 30, 2025
    risk 0.35cvss 6.4epss 0.00

    The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the blob_to_file() function in all versions up to, and including, 2.0.7. This makes it possible for authenticated attackers, with…

  • CVE-2025-31979MedAug 28, 2025
    risk 0.35cvss 5.4epss 0.00

    A File Upload Validation Bypass vulnerability has been identified in the HCL BigFix SM, where the application fails to properly enforce file type restrictions during the upload process. An attacker may exploit this flaw to upload malicious or unauthorized files, such as scripts,…

  • CVE-2025-43750MedAug 20, 2025
    risk 0.35cvss 6.5epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to…