VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 188 of 217
  • CVE-2025-55135MedAug 7, 2025
    risk 0.35cvss 6.4epss 0.00

    In Agora Foundation Agora fall23-Alpha1 before 690ce56, there is XSS via a profile picture to server/controller/userController.js. Formats other than PNG, JPEG, and WEBP are permitted by server/routes/userRoutes.js; this includes SVG.

  • CVE-2025-45855MedJun 3, 2025
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in the component /upload/GoodsCategory/image of erupt v1.12.19 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-11390MedMay 1, 2025
    risk 0.35cvss 5.4epss 0.00

    Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.

  • CVE-2024-13355MedJan 16, 2025
    risk 0.35cvss 5.4epss 0.00

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for…

  • CVE-2024-12042MedDec 13, 2024
    risk 0.35cvss 5.4epss 0.00

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it…

  • CVE-2024-45965MedOct 2, 2024
    risk 0.35cvss 6.4epss 0.00

    Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x and 5.5..x before 5.5.6.

  • CVE-2024-0757MedJun 4, 2024
    risk 0.35cvss 5.4epss 0.01

    The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

  • CVE-2024-34913MedMay 15, 2024
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-34909MedMay 15, 2024
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-34906MedMay 15, 2024
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-28890MedApr 23, 2024
    risk 0.35cvss 5.3epss 0.01

    Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a…

  • CVE-2024-3344MedApr 11, 2024
    risk 0.35cvss 6.4epss 0.00

    The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2024-2334MedApr 9, 2024
    risk 0.35cvss 6.4epss 0.00

    The Template Kit – Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template upload functionality in all versions up to, and including, 1.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2024-31454MedApr 9, 2024
    risk 0.35cvss 6.5epss 0.01

    PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which is designed for uploading files, allows an attacker who received the id of a file distribution to change the files that are in this…

  • CVE-2024-31453MedApr 9, 2024
    risk 0.35cvss 6.5epss 0.01

    PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on the endpoint, which allows users to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution.…

  • CVE-2024-2406MedMar 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index of the file /app/admin/controller/Upload.php. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2024-25994MedMar 12, 2024
    risk 0.35cvss 5.3epss 0.01

    An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

  • CVE-2024-23946MedFeb 29, 2024
    risk 0.35cvss 5.3epss 0.03

    Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

  • CVE-2023-51806MedJan 12, 2024
    risk 0.35cvss 5.4epss 0.01

    File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

  • CVE-2023-6102MedNov 13, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affected is an unknown function of the file /Content/Plugins/uploader/FileChoose.html?fileUrl=/Upload/File/Pics/&parent. The manipulation leads to unrestricted…