VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 208 of 215
  • CVE-2026-14906MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This vulnerability was fixed in Firefox for iOS 152.4.

  • CVE-2026-57719CriJul 13, 2026
    risk 0.00cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

  • CVE-2026-57710CriJul 13, 2026
    risk 0.00cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

  • CVE-2026-15539MedJul 13, 2026
    risk 0.00cvss 4.7epss 0.00

    A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be…

  • CVE-2026-15553MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download.

  • CVE-2026-15518MedJul 13, 2026
    risk 0.00cvss 4.7epss 0.00

    A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of the component Media Library Insert Page. Such manipulation of the argument…

  • CVE-2026-15488HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in hcr707305003 shiroiAdmin 1.1/1.3. Affected is the function FileController::upload of the file app/common/controller/FileController.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched…

  • CVE-2026-61448LowJul 11, 2026
    risk 0.00cvss epss 0.00

    Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed…

  • CVE-2026-57828HigJul 11, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

  • CVE-2026-57827CriJul 11, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2026-2354HigJul 11, 2026
    risk 0.00cvss 8.8epss 0.01

    The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` function in all versions up to, and including, 1.4.6. The `upload_extension_files()` function hooks into WordPress's…

  • CVE-2026-15282CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-14894CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.03

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the…

  • CVE-2026-13430HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.01

    The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass,…

  • CVE-2026-43752MedJul 9, 2026
    risk 0.00cvss 4.9epss 0.00

    An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.

  • CVE-2026-15158CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.01

    The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename…

  • CVE-2026-58654MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType) beginning with 'image/' and does not…

  • CVE-2026-58480CriJul 8, 2026
    risk 0.00cvss 9.8epss 0.02

    Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews…

  • CVE-2026-14489HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.01

    The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to…

  • CVE-2026-14158HigJul 8, 2026
    risk 0.00cvss 8.8epss 0.01

    The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. This is due to missing capability check and nonce verification on the…