VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 64 of 216
  • CVE-2026-9102CriMay 20, 2026
    risk 0.61cvss epss 0.01

    A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape…

  • CVE-2019-25714CriApr 21, 2026
    risk 0.61cvss epss 0.01

    Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads.…

  • CVE-2012-10064CriJan 16, 2026
    risk 0.61cvss epss 0.01

    Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file…

  • CVE-2011-10041CriJan 15, 2026
    risk 0.61cvss epss 0.01

    Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow…

  • CVE-2020-36847CriJul 12, 2025
    risk 0.61cvss 9.8epss 0.18

    The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to…

  • CVE-2025-34511HigJun 17, 2025
    risk 0.61cvss 8.8epss 0.16

    Sitecore PowerShell Extensions, an add-on to Sitecore Experience Manager (XM) and Experience Platform (XP), through version 7.0 is vulnerable to an unrestricted file upload issue. A remote, authenticated attacker can upload arbitrary files to the server using crafted HTTP…

  • CVE-2025-1980CriApr 16, 2025
    risk 0.61cvss epss 0.01

    The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If the server is misconfigured, as it was by default when installed at the turn of 2021 and 2022, it can result in Remote Code Execution. Refer to the Required…

  • CVE-2024-6366CriJul 29, 2024
    risk 0.61cvss 9.1epss 0.29

    The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

  • CVE-2024-6127CriJun 27, 2024
    risk 0.61cvss 9.8epss 0.10

    BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering…

  • CVE-2023-38098HigMay 3, 2024
    risk 0.61cvss 8.8epss 0.13

    NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Although…

  • CVE-2024-25832HigFeb 29, 2024
    risk 0.61cvss 8.8epss 0.13

    F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

  • CVE-2023-28725CriMar 22, 2023
    risk 0.61cvss 9.1epss 0.21

    General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in…

  • CVE-2022-47615CriJan 26, 2023
    risk 0.61cvss 9.3epss 0.05

    Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

  • CVE-2022-44384HigNov 17, 2022
    risk 0.61cvss 8.8epss 0.05

    An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-36711CriJul 16, 2022
    risk 0.61cvss 9.8epss 0.16

    WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.

  • CVE-2022-2102CriJun 24, 2022
    risk 0.61cvss 9.4epss 0.01

    Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing…

  • CVE-2022-1103HigMay 16, 2022
    risk 0.61cvss 8.8epss 0.16

    The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

  • CVE-2021-44673HigMar 10, 2022
    risk 0.61cvss 8.8epss 0.09

    A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.

  • CVE-2021-46360HigFeb 9, 2022
    risk 0.61cvss 8.8epss 0.09

    Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.

  • CVE-2020-28688HigNov 17, 2020
    risk 0.61cvss 8.8epss 0.12

    The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.