VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 20 of 222
  • CVE-2026-40746CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

  • CVE-2026-39589CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

  • CVE-2026-27041CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

  • CVE-2026-25446CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

  • CVE-2026-22327CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions.

  • CVE-2025-60218CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions.

  • CVE-2024-52488CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

  • CVE-2026-40750CriJun 16, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

  • CVE-2026-39591CriJun 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

  • CVE-2026-50873CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

  • CVE-2018-25436CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file…

  • CVE-2026-53787CriJun 12, 2026
    risk 0.64cvss 9.8epss 0.06

    Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint…

  • CVE-2026-11839CriJun 11, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.002 before V2026.06.003.

  • CVE-2026-7852CriJun 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.

  • CVE-2024-58349CriJun 8, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme…

  • CVE-2024-58348CriJun 8, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitrary files by accessing the ups.php endpoint. Attackers can upload PHP files through the file upload form in the plugin directory to…

  • CVE-2026-10071CriMay 29, 2026
    risk 0.64cvss 9.8epss 0.01

    DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2026-42748CriMay 27, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue affects WPify Woo Czech: from n/a through <= 5.4.1.

  • CVE-2026-6960CriMay 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated…

  • CVE-2026-6555CriMay 20, 2026
    risk 0.64cvss 9.8epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files…