CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,297)
page 210 of 215| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-13165 | Hig | 0.00 | — | 0.00 | Jun 29, 2026 | SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a… | ||
| CVE-2026-13553 | Hig | 0.00 | 7.3 | 0.00 | Jun 29, 2026 | A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the… | ||
| CVE-2026-13547 | Hig | 0.00 | 7.3 | 0.00 | Jun 29, 2026 | A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be… | ||
| CVE-2026-57658 | Cri | 0.00 | 9.1 | 0.00 | Jun 26, 2026 | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. | ||
| CVE-2026-56059 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | ||
| CVE-2026-56058 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | ||
| CVE-2026-56027 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | ||
| CVE-2026-57700 | Cri | 0.00 | 10.0 | 0.00 | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6. | ||
| CVE-2026-48946 | Med | 0.00 | 6.3 | 0.00 | Jun 25, 2026 | The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute… | ||
| CVE-2026-48945 | Med | 0.00 | 5.3 | 0.00 | Jun 25, 2026 | The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access. | ||
| CVE-2026-41517 | Non | 0.00 | — | 0.00 | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in… | ||
| CVE-2026-26975 | Hig | 0.00 | 8.8 | 0.01 | Feb 20, 2026 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API… | ||
| CVE-2025-66480 | Cri | 0.00 | 9.8 | 0.01 | Feb 2, 2026 | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an… | ||
| CVE-2026-23499 | Med | 0.00 | 5.4 | 0.00 | Jan 21, 2026 | Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript. Depending on the deployment… | ||
| CVE-2026-1021 | 0.00 | — | 0.01 | Jan 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||
| CVE-2026-22799 | Hig | 0.00 | 8.8 | 0.01 | Jan 12, 2026 | Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers… | ||
| CVE-2026-22789 | Med | 0.00 | 5.4 | 0.00 | Jan 12, 2026 | WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts,… | ||
| CVE-2026-22783 | Cri | 0.00 | 9.6 | 0.00 | Jan 12, 2026 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in… | ||
| CVE-2025-66449 | Hig | 0.00 | 8.8 | 0.01 | Dec 16, 2025 | ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user… | ||
| CVE-2025-67506 | Cri | 0.00 | 9.8 | 0.02 | Dec 10, 2025 | PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by… |
- risk 0.00cvss —epss 0.00
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a…
- risk 0.00cvss 7.3epss 0.00
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the…
- risk 0.00cvss 7.3epss 0.00
A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be…
- risk 0.00cvss 9.1epss 0.00
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
- risk 0.00cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
- risk 0.00cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
- risk 0.00cvss 9.9epss 0.00
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
- risk 0.00cvss 10.0epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
- risk 0.00cvss 6.3epss 0.00
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute…
- risk 0.00cvss 5.3epss 0.00
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access.
- risk 0.00cvss —epss 0.00
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in…
- risk 0.00cvss 8.8epss 0.01
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…
- risk 0.00cvss 9.8epss 0.01
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an…
- risk 0.00cvss 5.4epss 0.00
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript. Depending on the deployment…
- CVE-2026-1021Jan 16, 2026risk 0.00cvss —epss 0.01
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.00cvss 8.8epss 0.01
Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers…
- risk 0.00cvss 5.4epss 0.00
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts,…
- risk 0.00cvss 9.6epss 0.00
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in…
- risk 0.00cvss 8.8epss 0.01
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user…
- risk 0.00cvss 9.8epss 0.02
PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by…