VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 22 of 222
  • CVE-2026-24960CriMar 5, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

  • CVE-2025-68555CriMar 5, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Nutrie nutrie allows Upload a Web Shell to a Web Server.This issue affects Nutrie: from n/a through < 2.0.1.

  • CVE-2025-68554CriMar 5, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1.

  • CVE-2025-68553CriMar 5, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1.

  • CVE-2025-14532CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

  • CVE-2025-69403CriFeb 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue affects Bravis Addons: from n/a through <= 1.3.0.

  • CVE-2025-68549CriFeb 20, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Wiguard wiguard allows Upload a Web Shell to a Web Server.This issue affects Wiguard: from n/a through < 2.0.1.

  • CVE-2026-1405CriFeb 19, 2026
    risk 0.64cvss 9.8epss 0.03

    The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-2550CriFeb 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.…

  • CVE-2026-1306CriFeb 14, 2026
    risk 0.64cvss 9.8epss 0.04

    The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2026-1358CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

  • CVE-2025-14014CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before…

  • CVE-2020-37090CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

  • CVE-2025-69981CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as…

  • CVE-2025-61506CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.

  • CVE-2026-25200CriFeb 2, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.

  • CVE-2025-57795CriJan 28, 2026
    risk 0.64cvss 9.9epss 0.01

    Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution.

  • CVE-2025-69559CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

  • CVE-2025-69565CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

  • CVE-2025-13374CriJan 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files…