CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,434)
page 8 of 222| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38836 | Hig | 0.66 | 8.8 | 0.76 | Aug 21, 2023 | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | ||
| CVE-2023-33404 | Cri | 0.66 | 9.8 | 0.26 | Jun 26, 2023 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | ||
| CVE-2022-37159 | Cri | 0.66 | 9.8 | 0.26 | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. | ||
| CVE-2022-30887 | Cri | 0.66 | 9.8 | 0.26 | May 20, 2022 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||
| CVE-2022-28021 | Cri | 0.66 | 9.8 | 0.24 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | ||
| CVE-2021-42669 | Cri | 0.66 | 9.8 | 0.23 | Nov 5, 2021 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by… | ||
| CVE-2021-40531 | Cri | 0.66 | 9.8 | 0.33 | Sep 6, 2021 | Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to… | ||
| CVE-2021-20022 | Hig | 0.66 | 7.2 | 0.17 | KEV | Apr 9, 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | |
| CVE-2020-11108 | Hig | 0.66 | 8.8 | 0.78 | May 11, 2020 | The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to… | ||
| CVE-2019-10267 | Hig | 0.66 | 8.8 | 0.75 | Jul 26, 2019 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the… | ||
| CVE-2019-7268 | Cri | 0.66 | 10.0 | 0.06 | Jul 2, 2019 | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload. | ||
| CVE-2018-7836 | Cri | 0.66 | 9.8 | 0.32 | Dec 24, 2018 | An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files. | ||
| CVE-2026-4357 | Cri | 0.65 | 10.0 | 0.00 | Sep 2, 2026 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. | ||
| CVE-2026-84147 | — | Cri | 0.65 | — | 0.01 | Sep 1, 2026 | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the… | |
| CVE-2026-81780 | Cri | 0.65 | 10.0 | 0.00 | Aug 31, 2026 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | ||
| CVE-2026-82970 | Cri | 0.65 | 10.0 | 0.00 | Aug 31, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. | ||
| CVE-2026-75949 | Cri | 0.65 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak… | ||
| CVE-2026-74803 | Cri | 0.65 | — | 0.00 | Aug 19, 2026 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | ||
| CVE-2026-66665 | Cri | 0.65 | 10.0 | 0.00 | Aug 6, 2026 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | ||
| CVE-2026-48283 | Cri | 0.65 | 10.0 | 0.01 | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope… |
- risk 0.66cvss 8.8epss 0.76
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
- risk 0.66cvss 9.8epss 0.26
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
- risk 0.66cvss 9.8epss 0.26
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
- risk 0.66cvss 9.8epss 0.26
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
- risk 0.66cvss 9.8epss 0.24
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.
- risk 0.66cvss 9.8epss 0.23
A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by…
- risk 0.66cvss 9.8epss 0.33
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to…
- risk 0.66cvss 7.2epss 0.17
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- risk 0.66cvss 8.8epss 0.78
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to…
- risk 0.66cvss 8.8epss 0.75
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the…
- risk 0.66cvss 10.0epss 0.06
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
- risk 0.66cvss 9.8epss 0.32
An unrestricted Upload of File with Dangerous Type vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow upload and execution of malicious files.
- risk 0.65cvss 10.0epss 0.00
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
- risk 0.65cvss —epss 0.01
This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the…
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
- risk 0.65cvss 10.0epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
- risk 0.65cvss —epss 0.00
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…
- risk 0.65cvss —epss 0.00
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
- risk 0.65cvss 10.0epss 0.00
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- risk 0.65cvss 10.0epss 0.01
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope…