VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 80 of 216
  • CVE-2020-37117HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.01

    jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url…

  • CVE-2026-20098HigFeb 4, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper…

  • CVE-2026-25510CriFeb 3, 2026
    risk 0.57cvss 9.9epss 0.01

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the…

  • CVE-2020-37073HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing…

  • CVE-2025-65875HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-37113HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.01

    GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by…

  • CVE-2026-25201HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.

  • CVE-2020-37023HigJan 30, 2026
    risk 0.57cvss 8.8epss 0.01

    Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request…

  • CVE-2020-37009HigJan 29, 2026
    risk 0.57cvss 8.8epss 0.01

    MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system…

  • CVE-2020-36942HigJan 27, 2026
    risk 0.57cvss 8.8epss 0.01

    Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web…

  • CVE-2021-47904HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.01

    PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

  • CVE-2021-47888HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.01

    Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the…

  • CVE-2025-33015HigJan 20, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface.

  • CVE-2026-21625HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.00

    User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by file extensions, no mime type checks are happening.

  • CVE-2021-47788HigJan 16, 2026
    risk 0.57cvss 8.8epss 0.01

    WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve…

  • CVE-2025-67077HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.00

    File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions also guest users, via the UploadTmpFile action.

  • CVE-2021-47758HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor…

  • CVE-2021-47757HigJan 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the…

  • CVE-2022-50936HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.01

    WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute…

  • CVE-2022-50898HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.01

    NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism…