CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,297)
page 8 of 215| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38836 | Hig | 0.66 | 8.8 | 0.69 | Aug 21, 2023 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | ||
| CVE-2023-33404 | Cri | 0.66 | 9.8 | 0.26 | Jun 26, 2023 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | ||
| CVE-2022-37159 | Cri | 0.66 | 9.8 | 0.25 | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | ||
| CVE-2022-30887 | Cri | 0.66 | 9.8 | 0.26 | May 20, 2022 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||
| CVE-2022-28021 | Cri | 0.66 | 9.8 | 0.24 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | ||
| CVE-2021-42669 | Cri | 0.66 | 9.8 | 0.23 | Nov 5, 2021 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by… | ||
| CVE-2021-40531 | Cri | 0.66 | 9.8 | 0.33 | Sep 6, 2021 | Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to… | ||
| CVE-2021-20022 | Hig | 0.66 | 7.2 | 0.17 | KEV | Apr 9, 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | |
| CVE-2020-11108 | Hig | 0.66 | 8.8 | 0.78 | May 11, 2020 | The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to… | ||
| CVE-2019-10267 | Hig | 0.66 | 8.8 | 0.75 | Jul 26, 2019 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the… | ||
| CVE-2019-7268 | Cri | 0.66 | 10.0 | 0.06 | Jul 2, 2019 | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload. | ||
| CVE-2018-7836 | Cri | 0.66 | 9.8 | 0.32 | Dec 24, 2018 | An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files. | ||
| CVE-2026-66665 | Cri | 0.65 | 10.0 | 0.00 | Aug 6, 2026 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | ||
| CVE-2025-69129 | Cri | 0.65 | 10.0 | 0.00 | Jun 17, 2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions. | ||
| CVE-2026-40772 | Cri | 0.65 | 10.0 | 0.00 | Jun 15, 2026 | Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions. | ||
| CVE-2026-40412 | Cri | 0.65 | 10.0 | 0.01 | May 22, 2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-45444 | Cri | 0.65 | 10.0 | 0.00 | May 20, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6. | ||
| CVE-2026-30821 | Cri | 0.65 | 9.8 | 0.15 | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates… | ||
| CVE-2026-24729 | Cri | 0.65 | — | 0.00 | Jan 30, 2026 | An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file. | ||
| CVE-2026-24815 | Cri | 0.65 | — | 0.00 | Jan 27, 2026 | Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before… |
- risk 0.66cvss 8.8epss 0.69
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
- risk 0.66cvss 9.8epss 0.26
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
- risk 0.66cvss 9.8epss 0.25
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
- risk 0.66cvss 9.8epss 0.26
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
- risk 0.66cvss 9.8epss 0.24
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.
- risk 0.66cvss 9.8epss 0.23
A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by…
- risk 0.66cvss 9.8epss 0.33
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to…
- risk 0.66cvss 7.2epss 0.17
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- risk 0.66cvss 8.8epss 0.78
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to…
- risk 0.66cvss 8.8epss 0.75
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the…
- risk 0.66cvss 10.0epss 0.06
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
- risk 0.66cvss 9.8epss 0.32
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
- risk 0.65cvss 10.0epss 0.01
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 10.0epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.
- risk 0.65cvss 9.8epss 0.15
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates…
- risk 0.65cvss —epss 0.00
An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.
- risk 0.65cvss —epss 0.00
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before…