VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 64 of 222
  • CVE-2015-1000000CriOct 6, 2016
    risk 0.64cvss 9.8epss 0.03

    Remote file upload vulnerability in mailcwp v1.99 wordpress plugin

  • CVE-2016-5050CriAug 26, 2016
    risk 0.64cvss 9.8epss 0.03

    Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.

  • CVE-2025-61678HigOct 14, 2025
    risk 0.63cvss —epss 0.44

    FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting…

  • CVE-2025-7441CriAug 16, 2025
    risk 0.63cvss 9.8epss 0.40

    The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook REST-API endpoint that does not have sufficient filetype validation. This makes it possible…

  • CVE-2014-125126CriJul 31, 2025
    risk 0.63cvss —epss 0.02

    An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict…

  • CVE-2025-3835CriJun 9, 2025
    risk 0.63cvss 9.6epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

  • CVE-2022-47878HigMay 2, 2023
    risk 0.63cvss 8.8epss 0.36

    Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the…

  • CVE-2022-48194HigDec 30, 2022
    risk 0.63cvss 8.8epss 0.33

    TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

  • CVE-2022-31161CriJul 15, 2022
    risk 0.63cvss 10.0epss 0.28

    Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0…

  • CVE-2021-34995HigJan 13, 2022
    risk 0.63cvss 8.8epss 0.69

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2021-32630CriMay 20, 2021
    risk 0.63cvss 9.6epss 0.02

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload…

  • CVE-2020-19364HigJan 20, 2021
    risk 0.63cvss 8.8epss 0.71

    OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

  • CVE-2015-6000HigFeb 6, 2020
    risk 0.63cvss 8.8epss 0.40

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an…

  • CVE-2020-5514CriJan 6, 2020
    risk 0.63cvss 9.1epss 0.44

    Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

  • CVE-2019-15813HigSep 4, 2019
    risk 0.63cvss 8.8epss 0.33

    Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.

  • CVE-2019-4013CriApr 10, 2019
    risk 0.63cvss 9.0epss 0.13

    IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.

  • CVE-2018-6152CriDec 4, 2018
    risk 0.63cvss 9.6epss 0.01

    The implementation of the Page.downloadBehavior backend unconditionally marked downloaded files as safe, regardless of file type in Google Chrome prior to 66.0.3359.117 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox…

  • CVE-2018-12980HigJul 12, 2018
    risk 0.63cvss 8.8epss 0.30

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

  • CVE-2017-16524HigNov 6, 2017
    risk 0.63cvss 8.8epss 0.30

    Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a…

  • CVE-2026-28192CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.