VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 6 of 215
  • CVE-2012-10054CriAug 13, 2025
    risk 0.67cvss 9.8epss 0.03

    Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the…

  • CVE-2012-10030CriAug 5, 2025
    risk 0.67cvss 9.8epss 0.02

    FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no…

  • CVE-2013-10040CriJul 31, 2025
    risk 0.67cvss 9.8epss 0.03

    ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker…

  • CVE-2015-10137CriJul 22, 2025
    risk 0.67cvss 9.8epss 0.03

    The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload…

  • CVE-2015-10138CriJul 19, 2025
    risk 0.67cvss 9.8epss 0.02

    The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to…

  • CVE-2012-10019CriJul 19, 2025
    risk 0.67cvss 9.8epss 0.02

    The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which…

  • CVE-2025-34111CriJul 15, 2025
    risk 0.67cvss 9.8epss 0.02

    An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of…

  • CVE-2020-36849CriJul 12, 2025
    risk 0.67cvss 9.8epss 0.05

    The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php file in versions up to, and including, 3.0.3. This makes it possible for…

  • CVE-2024-8856CriNov 16, 2024
    risk 0.67cvss 9.8epss 0.94

    The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. This makes it possible…

  • CVE-2024-9932CriOct 26, 2024
    risk 0.67cvss 9.8epss 0.36

    The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2024-44849CriSep 9, 2024
    risk 0.67cvss 9.8epss 0.46

    Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

  • CVE-2024-31777CriJun 13, 2024
    risk 0.67cvss 9.8epss 0.04

    File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

  • CVE-2023-39115CriAug 16, 2023
    risk 0.67cvss 9.8epss 0.08

    install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

  • CVE-2023-32564CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.44

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

  • CVE-2023-32562CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.46

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

  • CVE-2022-34128CriApr 16, 2023
    risk 0.67cvss 9.8epss 0.08

    The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

  • CVE-2022-46020CriDec 20, 2022
    risk 0.67cvss 9.8epss 0.39

    WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.

  • CVE-2022-0888CriMar 23, 2022
    risk 0.67cvss 9.8epss 0.39

    The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to…

  • CVE-2021-32955CriAug 30, 2021
    risk 0.67cvss 9.8epss 0.37

    Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to remotely execute code.

  • CVE-2021-24370CriJun 21, 2021
    risk 0.67cvss 9.8epss 0.47

    The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.