VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,434)

page 8 of 222
  • CVE-2023-38836HigAug 21, 2023
    risk 0.66cvss 8.8epss 0.76

    File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

  • CVE-2023-33404CriJun 26, 2023
    risk 0.66cvss 9.8epss 0.26

    An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.

  • CVE-2022-37159CriAug 25, 2022
    risk 0.66cvss 9.8epss 0.26

    Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

  • CVE-2022-30887CriMay 20, 2022
    risk 0.66cvss 9.8epss 0.26

    Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

  • CVE-2022-28021CriApr 21, 2022
    risk 0.66cvss 9.8epss 0.24

    Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.

  • CVE-2021-42669CriNov 5, 2021
    risk 0.66cvss 9.8epss 0.23

    A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by…

  • CVE-2021-40531CriSep 6, 2021
    risk 0.66cvss 9.8epss 0.33

    Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to…

  • CVE-2021-20022HigKEVApr 9, 2021
    risk 0.66cvss 7.2epss 0.17

    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

  • CVE-2020-11108HigMay 11, 2020
    risk 0.66cvss 8.8epss 0.78

    The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to…

  • CVE-2019-10267HigJul 26, 2019
    risk 0.66cvss 8.8epss 0.75

    An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the…

  • CVE-2019-7268CriJul 2, 2019
    risk 0.66cvss 10.0epss 0.06

    Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.

  • CVE-2018-7836CriDec 24, 2018
    risk 0.66cvss 9.8epss 0.32

    An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.

  • CVE-2026-4357CriSep 2, 2026
    risk 0.65cvss 10.0epss 0.00

    The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

  • CVE-2026-84147CriSep 1, 2026
    risk 0.65cvss —epss 0.01

    This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the…

  • CVE-2026-81780CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.00

    Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

  • CVE-2026-82970CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

  • CVE-2026-75949CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…

  • CVE-2026-74803CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

  • CVE-2026-66665CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

  • CVE-2026-48283CriJun 30, 2026
    risk 0.65cvss 10.0epss 0.01

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope…