VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,297)

page 7 of 215
  • CVE-2021-24284CriMay 14, 2021
    risk 0.67cvss 9.8epss 0.42

    The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as…

  • CVE-2021-3120CriFeb 22, 2021
    risk 0.67cvss 9.8epss 0.37

    An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability,…

  • CVE-2011-4906CriFeb 12, 2020
    risk 0.67cvss 9.8epss 0.10

    Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

  • CVE-2012-5190CriJan 21, 2020
    risk 0.67cvss 9.8epss 0.05

    Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability

  • CVE-2020-7246HigJan 21, 2020
    risk 0.67cvss 8.8epss 0.83

    A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of…

  • CVE-2012-2226CriJan 9, 2020
    risk 0.67cvss 9.8epss 0.07

    Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

  • CVE-2019-18952CriNov 13, 2019
    risk 0.67cvss 9.8epss 0.45

    SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

  • CVE-2019-9623CriMar 7, 2019
    risk 0.67cvss 9.8epss 0.08

    Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

  • CVE-2018-18793CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.10

    School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.

  • CVE-2018-9206CriOct 11, 2018
    risk 0.67cvss 9.8epss 0.97

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

  • CVE-2018-11523CriMay 29, 2018
    risk 0.67cvss 9.8epss 0.10

    upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

  • CVE-2018-6411CriMay 26, 2018
    risk 0.67cvss 9.8epss 0.06

    An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.

  • CVE-2014-4912CriMar 22, 2018
    risk 0.67cvss 9.8epss 0.08

    An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.

  • CVE-2018-7316CriFeb 22, 2018
    risk 0.67cvss 9.8epss 0.08

    Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.

  • CVE-2017-15990CriOct 31, 2017
    risk 0.67cvss 9.8epss 0.08

    Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.

  • CVE-2017-15962CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.05

    iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

  • CVE-2025-6440CriOct 24, 2025
    risk 0.66cvss 9.8epss 0.31

    The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and…

  • CVE-2025-48148CriAug 20, 2025
    risk 0.66cvss 10.0epss 0.15

    Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.

  • CVE-2024-56064CriDec 31, 2024
    risk 0.66cvss 10.0epss 0.30

    Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

  • CVE-2024-29974CriJun 4, 2024
    risk 0.66cvss 9.8epss 0.23

    ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute…