VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 210 of 215
  • CVE-2026-13165HigJun 29, 2026
    risk 0.00cvss epss 0.00

    SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). An attacker who controls the served archive can insert a…

  • CVE-2026-13553HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of the argument image can lead to unrestricted upload. It is possible to launch the…

  • CVE-2026-13547HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown processing of the file /manage/resourceUpload/upload.do. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be…

  • CVE-2026-57658CriJun 26, 2026
    risk 0.00cvss 9.1epss 0.00

    Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

  • CVE-2026-56059CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

  • CVE-2026-56058CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

  • CVE-2026-56027CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

  • CVE-2026-57700CriJun 25, 2026
    risk 0.00cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

  • CVE-2026-48946MedJun 25, 2026
    risk 0.00cvss 6.3epss 0.00

    The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute…

  • CVE-2026-48945MedJun 25, 2026
    risk 0.00cvss 5.3epss 0.00

    The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries//`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access.

  • CVE-2026-41517NonMay 8, 2026
    risk 0.00cvss epss 0.00

    Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server compromise and persistent backdoor installation. This issue has been patched in…

  • CVE-2026-26975HigFeb 20, 2026
    risk 0.00cvss 8.8epss 0.01

    Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…

  • CVE-2025-66480CriFeb 2, 2026
    risk 0.00cvss 9.8epss 0.01

    Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an…

  • CVE-2026-23499MedJan 21, 2026
    risk 0.00cvss 5.4epss 0.00

    Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript. Depending on the deployment…

  • CVE-2026-1021Jan 16, 2026
    risk 0.00cvss epss 0.01

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-22799HigJan 12, 2026
    risk 0.00cvss 8.8epss 0.01

    Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers…

  • CVE-2026-22789MedJan 12, 2026
    risk 0.00cvss 5.4epss 0.00

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts,…

  • CVE-2026-22783CriJan 12, 2026
    risk 0.00cvss 9.6epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in…

  • CVE-2025-66449HigDec 16, 2025
    risk 0.00cvss 8.8epss 0.01

    ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user…

  • CVE-2025-67506CriDec 10, 2025
    risk 0.00cvss 9.8epss 0.02

    PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by…