CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,297)
page 7 of 215| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24284 | Cri | 0.67 | 9.8 | 0.42 | May 14, 2021 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as… | ||
| CVE-2021-3120 | Cri | 0.67 | 9.8 | 0.37 | Feb 22, 2021 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability,… | ||
| CVE-2011-4906 | Cri | 0.67 | 9.8 | 0.10 | Feb 12, 2020 | Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution. | ||
| CVE-2012-5190 | Cri | 0.67 | 9.8 | 0.05 | Jan 21, 2020 | Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability | ||
| CVE-2020-7246 | Hig | 0.67 | 8.8 | 0.83 | Jan 21, 2020 | A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of… | ||
| CVE-2012-2226 | Cri | 0.67 | 9.8 | 0.07 | Jan 9, 2020 | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file. | ||
| CVE-2019-18952 | Cri | 0.67 | 9.8 | 0.45 | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP. | ||
| CVE-2019-9623 | Cri | 0.67 | 9.8 | 0.08 | Mar 7, 2019 | Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php. | ||
| CVE-2018-18793 | Cri | 0.67 | 9.8 | 0.10 | Nov 16, 2018 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | ||
| CVE-2018-9206 | Cri | 0.67 | 9.8 | 0.97 | Oct 11, 2018 | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | ||
| CVE-2018-11523 | Cri | 0.67 | 9.8 | 0.10 | May 29, 2018 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. | ||
| CVE-2018-6411 | Cri | 0.67 | 9.8 | 0.06 | May 26, 2018 | An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection. | ||
| CVE-2014-4912 | Cri | 0.67 | 9.8 | 0.08 | Mar 22, 2018 | An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | ||
| CVE-2018-7316 | Cri | 0.67 | 9.8 | 0.08 | Feb 22, 2018 | Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action. | ||
| CVE-2017-15990 | Cri | 0.67 | 9.8 | 0.08 | Oct 31, 2017 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | ||
| CVE-2017-15962 | Cri | 0.67 | 9.8 | 0.05 | Oct 29, 2017 | iStock Management System 1.0 allows Arbitrary File Upload via user/profile. | ||
| CVE-2025-6440 | Cri | 0.66 | 9.8 | 0.31 | Oct 24, 2025 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and… | ||
| CVE-2025-48148 | Cri | 0.66 | 10.0 | 0.15 | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4. | ||
| CVE-2024-56064 | Cri | 0.66 | 10.0 | 0.30 | Dec 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | ||
| CVE-2024-29974 | Cri | 0.66 | 9.8 | 0.23 | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute… |
- risk 0.67cvss 9.8epss 0.42
The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'uploadFontIcon' AJAX action. The supplied zipfile being unzipped in the wp-content/uploads/kaswara/fonts_icon directory with no checks for malicious files such as…
- risk 0.67cvss 9.8epss 0.37
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability,…
- risk 0.67cvss 9.8epss 0.10
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
- risk 0.67cvss 9.8epss 0.05
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
- risk 0.67cvss 8.8epss 0.83
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code file via the profile photo functionality, by leveraging a path traversal vulnerability in the users['photop_preview'] delete photo feature, allowing bypass of…
- risk 0.67cvss 9.8epss 0.07
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
- risk 0.67cvss 9.8epss 0.45
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
- risk 0.67cvss 9.8epss 0.08
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
- risk 0.67cvss 9.8epss 0.10
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
- risk 0.67cvss 9.8epss 0.97
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
- risk 0.67cvss 9.8epss 0.10
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
- risk 0.67cvss 9.8epss 0.06
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
- risk 0.67cvss 9.8epss 0.08
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
- risk 0.67cvss 9.8epss 0.08
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
- risk 0.67cvss 9.8epss 0.08
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
- risk 0.67cvss 9.8epss 0.05
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
- risk 0.66cvss 9.8epss 0.31
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and…
- risk 0.66cvss 10.0epss 0.15
Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.
- risk 0.66cvss 10.0epss 0.30
Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.
- risk 0.66cvss 9.8epss 0.23
** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute…