VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,314)

page 67 of 216
  • CVE-2024-6220CriJul 17, 2024
    risk 0.60cvss 9.8epss 0.36

    The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload…

  • CVE-2023-50386HigFeb 9, 2024
    risk 0.60cvss 8.8epss 0.84

    Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. In…

  • CVE-2023-50564HigDec 14, 2023
    risk 0.60cvss 8.8epss 0.29

    An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.

  • CVE-2021-43421CriApr 7, 2022
    risk 0.60cvss 9.8epss 0.43

    A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remote malicious user to upload arbitrary files and execute PHP code.

  • CVE-2021-42362HigNov 17, 2021
    risk 0.60cvss 8.8epss 0.80

    The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can…

  • CVE-2021-20130HigOct 13, 2021
    risk 0.60cvss 8.8epss 0.33

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.

  • CVE-2020-36167CriJan 6, 2021
    risk 0.60cvss 9.3epss 0.00

    An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation folder. This library in turn attempts to load the /usr/local/ssl/openssl.cnf…

  • CVE-2020-24407CriNov 9, 2020
    risk 0.60cvss 9.1epss 0.05

    Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an unsafe file upload vulnerability that could result in arbitrary code execution. This vulnerability could be abused by authenticated users with administrative permissions to the System/Data and Transfer/Import…

  • CVE-2020-0932HigApr 15, 2020
    risk 0.60cvss 8.8epss 0.31

    A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929,…

  • CVE-2019-7669HigJul 1, 2019
    risk 0.60cvss 8.8epss 0.31

    Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.

  • CVE-2019-8942HigFeb 20, 2019
    risk 0.60cvss 8.8epss 0.83

    WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by…

  • CVE-2018-11736CriJun 5, 2018
    risk 0.60cvss 9.8epss 0.09

    An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.

  • CVE-2017-14840HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.04

    TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.

  • CVE-2017-14839HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.04

    TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.

  • CVE-2017-14838HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.04

    TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.

  • CVE-2026-3418CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher…

  • CVE-2026-50006criJul 14, 2026
    risk 0.59cvss epss

    ## Summary Anyquery's `server` mode does not disable or restrict native SQLite disk manipulation commands. Unauthenticated attackers connecting to the MySQL-compatible server port can use the `ATTACH DATABASE` command to write arbitrary SQLite databases to any path on the…

  • CVE-2026-53649criJul 8, 2026
    risk 0.59cvss epss

    # Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0) **Severity:** Critical **CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) **Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS **Reporter:** cstover **Date:** 2026-05-27 --- …

  • CVE-2026-52705CriJun 17, 2026
    risk 0.59cvss 9.0epss 0.00

    Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.

  • CVE-2026-9067CriJun 10, 2026
    risk 0.59cvss 9.1epss 0.01

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users…