VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 200 of 217
  • CVE-2021-46078MedJan 6, 2022
    risk 0.31cvss 4.8epss 0.01

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

  • CVE-2018-15424MedOct 5, 2018
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

  • CVE-2022-42449MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications

  • CVE-2022-27562MedApr 30, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript in deployed applications.

  • CVE-2022-44760MedApr 24, 2025
    risk 0.30cvss 4.6epss 0.00

    Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

  • CVE-2024-40513MedJan 16, 2025
    risk 0.30cvss 4.6epss 0.00

    An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.

  • CVE-2021-3915MedNov 13, 2021
    risk 0.30cvss 5.7epss 0.01

    bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2026-27146MedFeb 21, 2026
    risk 0.29cvss 4.5epss 0.00

    GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated…

  • CVE-2025-14632MedJan 17, 2026
    risk 0.29cvss 4.4epss 0.00

    The Filr – Secure document library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unrestricted file upload in all versions up to, and including, 1.2.11 due to insufficient file type restrictions in the FILR_Uploader class. This makes it possible for…

  • CVE-2025-48953MedJun 3, 2025
    risk 0.29cvss 5.5epss 0.00

    Umbraco is an ASP.NET content management system (CMS). Starting in version 14.0.0 and prior to versions 15.4.2 and 16.0.0, it's possible to upload a file that doesn't adhere with the configured allowable file extensions via a manipulated API request. The issue is patched in…

  • CVE-2024-55417MedJan 30, 2025
    risk 0.29cvss 4.3epss 0.13

    DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

  • CVE-2024-11404MedNov 20, 2024
    risk 0.29cvss 5.5epss 0.00

    Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS. This issue affects django Filer: from 3 before 3.3.

  • CVE-2022-40896MedJul 19, 2023
    risk 0.29cvss 5.5epss 0.01

    A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.

  • CVE-2017-12332MedNov 30, 2017
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated, local attacker to write a file to arbitrary locations. The vulnerability is due to insufficient restrictions in the patch installation process. An attacker could exploit this…

  • CVE-2026-53948MedJun 24, 2026
    risk 0.28cvss 5.4epss 0.00

    Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage…

  • CVE-2025-59872MedJun 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the server by uploading a file known as a web shell, which allows you to execute arbitrary code or…

  • CVE-2026-22707MedMay 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restrictions (`plugin.upload.security.allowedTypes` and `deniedTypes`). The same…

  • CVE-2018-25168MedMar 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by submitting crafted POST requests. Attackers can forge requests to the /public/admin/user/submitnew endpoint with user…

  • CVE-2026-2976MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Download Endpoint. This manipulation of the argument file_path causes…

  • CVE-2026-24673MedFeb 3, 2026
    risk 0.28cvss 4.3epss 0.00

    The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding them inside ZIP archives and extracting…