VYPR

CWE-434

Unrestricted Upload of File with Dangerous Type

BaseDraftLikelihood: Medium

Description

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (4,316)

page 81 of 216
  • CVE-2025-46068HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

  • CVE-2025-15158HigJan 7, 2026
    risk 0.57cvss 8.8epss 0.00

    The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Author-level access…

  • CVE-2025-15240HigJan 5, 2026
    risk 0.57cvss 8.8epss 0.00

    QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2025-55061HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.00

    CWE-434 Unrestricted Upload of File with Dangerous Type

  • CVE-2025-2155HigDec 24, 2025
    risk 0.57cvss 8.8epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025.

  • CVE-2023-53971HigDec 22, 2025
    risk 0.57cvss 8.8epss 0.00

    WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the…

  • CVE-2025-13329CriDec 20, 2025
    risk 0.57cvss 9.8epss 0.01

    The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for…

  • CVE-2023-53956HigDec 19, 2025
    risk 0.57cvss 8.8epss 0.01

    Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code…

  • CVE-2023-53952HigDec 19, 2025
    risk 0.57cvss 8.8epss 0.01

    Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the…

  • CVE-2025-14849HigDec 18, 2025
    risk 0.57cvss 8.8epss 0.01

    Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2023-53942HigDec 18, 2025
    risk 0.57cvss 8.8epss 0.01

    File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a…

  • CVE-2019-25229HigDec 18, 2025
    risk 0.57cvss 8.8epss 0.00

    An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system,…

  • CVE-2023-53933HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.01

    Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the…

  • CVE-2023-53924HigDec 17, 2025
    risk 0.57cvss 8.8epss 0.01

    UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system…

  • CVE-2023-53869HigDec 15, 2025
    risk 0.57cvss epss 0.01

    WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the…

  • CVE-2023-53868HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code…

  • CVE-2024-44598HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.00

    FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

  • CVE-2025-13094HigDec 13, 2025
    risk 0.57cvss 8.8epss 0.00

    The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level…

  • CVE-2025-12968HigDec 12, 2025
    risk 0.57cvss 8.8epss 0.01

    The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating…

  • CVE-2025-34506HigDec 11, 2025
    risk 0.57cvss 8.8epss 0.01

    WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the…