VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,339)

page 201 of 217
  • CVE-2025-65806MedDec 4, 2025
    risk 0.28cvss 4.3epss 0.00

    The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a nested ZIP (a ZIP containing another ZIP) where the inner archive contains an executable file (e.g. webshell.php). When the application extracts the uploaded…

  • CVE-2025-20287MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are…

  • CVE-2025-51489MedAug 19, 2025
    risk 0.28cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.

  • CVE-2025-50897MedAug 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd).…

  • CVE-2025-53891MedJul 15, 2025
    risk 0.28cvss 4.3epss 0.00

    The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found in the TIME LINE website where uploaded files (instruction/message media) are not strictly validated for type and size. A user may upload renamed or oversized…

  • CVE-2025-27127MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project-Server V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally…

  • CVE-2025-36519MedJun 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote…

  • CVE-2025-47866MedJun 17, 2025
    risk 0.28cvss 4.3epss 0.00

    An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations.

  • CVE-2025-47939MedMay 20, 2025
    risk 0.28cvss 5.4epss 0.00

    TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context.…

  • CVE-2025-25016MedMay 1, 2025
    risk 0.28cvss 4.3epss 0.00

    Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.

  • CVE-2025-3325MedApr 6, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in iteaj iboot 物联网网关 1.1.3. This affects an unknown part of the file /core/admin/pwd of the component Admin Password Handler. The manipulation of the argument ID leads to improper access controls. It is…

  • CVE-2025-27411MedMar 5, 2025
    risk 0.28cvss 5.4epss 0.00

    REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.

  • CVE-2024-10584MedDec 24, 2024
    risk 0.28cvss 5.4epss 0.00

    The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.6.16 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2024-11661MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file profile.php of the component Profile Image Handler. The manipulation of the argument image leads to…

  • CVE-2024-50652MedNov 15, 2024
    risk 0.28cvss 4.3epss 0.00

    A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

  • CVE-2024-9038MedSep 20, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation of the argument productimage1/productimage2/productimage3 leads to unrestricted…

  • CVE-2024-42375MedAug 13, 2024
    risk 0.28cvss 4.3epss 0.00

    SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrity of the application.

  • CVE-2024-36987MedJul 1, 2024
    risk 0.28cvss 4.3epss 0.00

    In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the admin or power Splunk roles could upload a file with an arbitrary extension using the indexing/preview…

  • CVE-2024-4945MedMay 16, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It is possible to launch the…

  • CVE-2024-3508MedApr 25, 2024
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.