VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (1,669)

page 66 of 84
  • CVE-2026-4875MedMar 26, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /admin/mod_amenities/index.php?view=add. This manipulation of the argument image causes unrestricted upload. The attack is possible to be…

  • CVE-2026-2666MedFeb 18, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched…

  • CVE-2026-2226MedFeb 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in DouPHP up to 1.9. This issue affects some unknown processing of the file /admin/file.php of the component ZIP File Handler. Such manipulation of the argument sql_filename leads to unrestricted upload. The attack can be launched remotely. The…

  • CVE-2026-2213MedFeb 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be…

  • CVE-2026-1742MedFeb 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in EFM ipTIME A8004T 14.18.2. Affected by this vulnerability is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi of the component VPN Service. Such manipulation leads to unrestricted upload. It is possible to launch the attack…

  • CVE-2026-1445MedJan 26, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability affects unknown code of the file controllers/books_center/upload_bookCover.php. Performing a manipulation of the argument book_cover results in unrestricted…

  • CVE-2026-1424MedJan 26, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

  • CVE-2026-1152MedJan 19, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code Image Handler. Such manipulation of the argument codeimg leads to unrestricted upload. The attack may be launched remotely. The…

  • CVE-2025-15495MedJan 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite.php. The manipulation of the argument image results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be…

  • CVE-2026-0566MedJan 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack is possible to be carried out remotely.…

  • CVE-2025-15415MedJan 1, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in xnx3 wangmarket up to 6.4. The impacted element is the function uploadImage of the file /sits/uploadImage.do of the component XML File Handler. The manipulation of the argument image leads to unrestricted upload. Remote exploitation of the…

  • CVE-2025-15360MedDec 30, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/common/UploadController.java of the component Product Information Edit Page. This manipulation of the argument File causes unrestricted…

  • CVE-2025-15262MedDec 30, 2025
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/edit.php of the component Site Logo Handler. Performing a manipulation of the argument image results in unrestricted upload. Remote exploitation of the…

  • CVE-2025-15197MedDec 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may…

  • CVE-2025-15110MedDec 27, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in jackq XCMS up to 3fab5342cc509945a7ce1b8ec39d19f701b89261. Affected is the function Upload of the file Admin/Home/Controller/ProductImageController.class.php of the component Backend. Such manipulation of the argument File leads to unrestricted…

  • CVE-2025-14642MedDec 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been…

  • CVE-2025-14641MedDec 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-14582MedDec 12, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing a manipulation of the argument userphoto results in unrestricted upload. The attack can be initiated…

  • CVE-2025-14530MedDec 11, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely.…

  • CVE-2025-14219MedDec 8, 2025
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. It is possible to launch…