CWE-434
Unrestricted Upload of File with Dangerous Type
Description
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1
CVEs mapped to this weakness (4,316)
page 81 of 216| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-46068 | Hig | 0.57 | 8.8 | 0.00 | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism | ||
| CVE-2025-15158 | Hig | 0.57 | 8.8 | 0.00 | Jan 7, 2026 | The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Author-level access… | ||
| CVE-2025-15240 | Hig | 0.57 | 8.8 | 0.00 | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | ||
| CVE-2025-55061 | — | Hig | 0.57 | 8.8 | 0.00 | Dec 29, 2025 | CWE-434 Unrestricted Upload of File with Dangerous Type | |
| CVE-2025-2155 | Hig | 0.57 | 8.8 | 0.00 | Dec 24, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025. | ||
| CVE-2023-53971 | Hig | 0.57 | 8.8 | 0.00 | Dec 22, 2025 | WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the… | ||
| CVE-2025-13329 | Cri | 0.57 | 9.8 | 0.01 | Dec 20, 2025 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for… | ||
| CVE-2023-53956 | Hig | 0.57 | 8.8 | 0.01 | Dec 19, 2025 | Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code… | ||
| CVE-2023-53952 | Hig | 0.57 | 8.8 | 0.01 | Dec 19, 2025 | Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the… | ||
| CVE-2025-14849 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code. | ||
| CVE-2023-53942 | Hig | 0.57 | 8.8 | 0.01 | Dec 18, 2025 | File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a… | ||
| CVE-2019-25229 | Hig | 0.57 | 8.8 | 0.00 | Dec 18, 2025 | An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system,… | ||
| CVE-2023-53933 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2025 | Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the… | ||
| CVE-2023-53924 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2025 | UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system… | ||
| CVE-2023-53869 | Hig | 0.57 | — | 0.01 | Dec 15, 2025 | WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the… | ||
| CVE-2023-53868 | Hig | 0.57 | 8.8 | 0.01 | Dec 15, 2025 | Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code… | ||
| CVE-2024-44598 | Hig | 0.57 | 8.8 | 0.00 | Dec 15, 2025 | FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module. | ||
| CVE-2025-13094 | Hig | 0.57 | 8.8 | 0.00 | Dec 13, 2025 | The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level… | ||
| CVE-2025-12968 | Hig | 0.57 | 8.8 | 0.01 | Dec 12, 2025 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating… | ||
| CVE-2025-34506 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the… |
- risk 0.57cvss 8.8epss 0.00
An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
- risk 0.57cvss 8.8epss 0.00
The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in the 'wpse_file_and_ext_webp' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Author-level access…
- risk 0.57cvss 8.8epss 0.00
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- risk 0.57cvss 8.8epss 0.00
CWE-434 Unrestricted Upload of File with Dangerous Type
- risk 0.57cvss 8.8epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Specto CM allows Remote Code Inclusion. This issue affects Specto CM: before 17032025.
- risk 0.57cvss 8.8epss 0.00
WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the…
- risk 0.57cvss 9.8epss 0.01
The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for…
- risk 0.57cvss 8.8epss 0.01
Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code…
- risk 0.57cvss 8.8epss 0.01
Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the…
- risk 0.57cvss 8.8epss 0.01
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
- risk 0.57cvss 8.8epss 0.01
File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a…
- risk 0.57cvss 8.8epss 0.00
An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system,…
- risk 0.57cvss 8.8epss 0.01
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the…
- risk 0.57cvss 8.8epss 0.01
UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system…
- risk 0.57cvss —epss 0.01
WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the…
- risk 0.57cvss 8.8epss 0.01
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code…
- risk 0.57cvss 8.8epss 0.00
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
- risk 0.57cvss 8.8epss 0.00
The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level…
- risk 0.57cvss 8.8epss 0.01
The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating…
- risk 0.57cvss 8.8epss 0.01
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrators to upload malicious modules. Attackers can craft a specially designed ZIP module with embedded PHP reverse shell code to gain remote system access when the…