CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,297)
page 2 of 215| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12800 | Cri | 0.73 | 9.8 | 0.79 | Jun 8, 2020 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | ||
| CVE-2013-0803 | Cri | 0.73 | 9.8 | 0.75 | Feb 11, 2020 | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | ||
| CVE-2013-7390 | Cri | 0.73 | 9.8 | 0.75 | Jan 27, 2020 | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the… | ||
| CVE-2014-8516 | Cri | 0.73 | 9.8 | 0.82 | Jan 3, 2020 | Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors. | ||
| CVE-2018-20526 | Cri | 0.73 | 9.8 | 0.73 | Mar 21, 2019 | Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php. | ||
| CVE-2015-8249 | Cri | 0.73 | 9.8 | 0.74 | Sep 28, 2017 | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | ||
| CVE-2017-9101 | Cri | 0.73 | 9.8 | 0.77 | May 21, 2017 | import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file. | ||
| CVE-2021-24499 | Cri | 0.72 | 9.8 | 0.60 | Aug 9, 2021 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the… | ||
| CVE-2021-26828 | Hig | 0.72 | 8.8 | 0.39 | KEV | Jun 11, 2021 | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | |
| CVE-2021-31207 | Med | 0.72 | 6.6 | 1.00 | KEV | May 11, 2021 | Microsoft Exchange Server Security Feature Bypass Vulnerability | |
| CVE-2020-35489 | Cri | 0.72 | 10.0 | 0.89 | Dec 17, 2020 | The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters. | ||
| CVE-2020-29597 | Cri | 0.72 | 9.8 | 0.71 | Dec 7, 2020 | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server. | ||
| CVE-2026-0740 | Cri | 0.71 | 9.8 | 0.58 | Apr 7, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for… | ||
| CVE-2024-23759 | Cri | 0.71 | 9.8 | 0.48 | Feb 12, 2024 | Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function. | ||
| CVE-2023-46264 | Cri | 0.71 | 9.8 | 0.90 | Dec 19, 2023 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | ||
| CVE-2021-43936 | Cri | 0.71 | 10.0 | 0.36 | Dec 6, 2021 | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution. | ||
| CVE-2021-37539 | Cri | 0.71 | 9.8 | 0.93 | Sep 27, 2021 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | ||
| CVE-2021-36356 | Cri | 0.71 | 9.8 | 0.54 | Aug 31, 2021 | KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an… | ||
| CVE-2011-4908 | Cri | 0.71 | 9.8 | 0.56 | Feb 12, 2020 | TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php. | ||
| CVE-2020-6754 | Cri | 0.71 | 9.8 | 0.95 | Feb 5, 2020 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,… |
- risk 0.73cvss 9.8epss 0.79
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
- risk 0.73cvss 9.8epss 0.75
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
- risk 0.73cvss 9.8epss 0.75
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…
- risk 0.73cvss 9.8epss 0.82
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
- risk 0.73cvss 9.8epss 0.73
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
- risk 0.73cvss 9.8epss 0.74
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
- risk 0.73cvss 9.8epss 0.77
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
- risk 0.72cvss 9.8epss 0.60
The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader did not perform nonce checks, or validate that the request is from a valid user in any other way. The endpoints allowed for uploading arbitrary files to the…
- risk 0.72cvss 8.8epss 0.39
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
- risk 0.72cvss 6.6epss 1.00
Microsoft Exchange Server Security Feature Bypass Vulnerability
- risk 0.72cvss 10.0epss 0.89
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
- risk 0.72cvss 9.8epss 0.71
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.
- risk 0.71cvss 9.8epss 0.58
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for…
- risk 0.71cvss 9.8epss 0.48
Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.
- risk 0.71cvss 9.8epss 0.90
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
- risk 0.71cvss 10.0epss 0.36
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.
- risk 0.71cvss 9.8epss 0.93
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
- risk 0.71cvss 9.8epss 0.54
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePathAjax.php accepts arbitrary executable pathnames (even though browseSystemFiles.php is no longer reachable via the GUI). NOTE: this issue exists because of an…
- risk 0.71cvss 9.8epss 0.56
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
- risk 0.71cvss 9.8epss 0.95
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,…