CWE-434— Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.— MITRE CWE catalog
4,557 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 18 of 92
- CVE-2020-26629CRITICALCVSS 9.8EG 9.82024-01-10
A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server.
- CVE-2024-0300CRITICALCVSS 9.8EG 9.82024-01-08
A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some unknown functionality of the file /useratte/userattestation.php of the component HTTP POST Req…
- CVE-2023-7212CRITICALCVSS 9.8EG 9.82024-01-07
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch th…
- CVE-2023-45724CRITICALCVSS 9.8EG 9.82024-01-03
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
- CVE-2024-0194CRITICALCVSS 9.8EG 9.82024-01-02
A vulnerability, which was classified as critical, has been found in CodeAstro Internet Banking System up to 1.0. This issue affects some unknown processing of the file pages_account.php of the component Profile Picture Handler. The manipu…
- CVE-2023-51412CRITICALCVSS 9.8EG 9.82023-12-29
Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
- CVE-2023-7159CRITICALCVSS 9.8EG 9.82023-12-29
A vulnerability was found in gopeak MasterLab up to 3.3.10. It has been declared as critical. Affected by this vulnerability is the function add/update of the file app/ctrl/admin/User.php. The manipulation of the argument avatar leads to u…
- CVE-2023-7147CRITICALCVSS 9.8EG 9.82023-12-29
A vulnerability, which was classified as critical, was found in gopeak MasterLab up to 3.3.10. Affected is the function base64ImageContent of the file app/ctrl/User.php. The manipulation of the argument image leads to unrestricted upload. …
- CVE-2023-50104CRITICALCVSS 9.8EG 9.82023-12-29
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
- CVE-2023-51034CRITICALCVSS 9.8EG 9.82023-12-22
TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.
- CVE-2023-42017CRITICALCVSS 9.8EG 9.82023-12-22
IBM Planning Analytics Local 2.0 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerabilit…
- CVE-2023-45603CRITICALCVSS 9.8EG 9.82023-12-20
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front En…
- CVE-2023-46264CRITICALCVSS 9.8EG 9.82023-12-19
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
- CVE-2023-46263CRITICALCVSS 9.8EG 9.82023-12-19
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
- CVE-2023-6902CRITICALCVSS 9.8EG 9.82023-12-17
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted …
- CVE-2023-6887CRITICALCVSS 9.8EG 9.82023-12-17
A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to…
- CVE-2023-6850CRITICALCVSS 9.8EG 9.82023-12-16
A vulnerability was found in kalcaddle KodExplorer up to 4.51.03. It has been declared as critical. This vulnerability affects unknown code of the file /index.php?pluginApp/to/yzOffice/getFile of the component API Endpoint Handler. The man…
- CVE-2023-48376CRITICALCVSS 9.8EG 9.82023-12-15
SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to pe…
- CVE-2023-48371CRITICALCVSS 9.8EG 9.82023-12-15
ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary syste…
- CVE-2023-48930CRITICALCVSS 9.8EG 9.82023-12-06
xinhu xinhuoa 2.2.1 contains a File upload vulnerability.
- CVE-2023-5636CRITICALCVSS 9.8EG 9.82023-12-01
Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. This issue affects Education Portal: before v1.1.
- CVE-2023-5604CRITICALCVSS 9.8EG 9.82023-11-27
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), po…
- CVE-2023-41998CRITICALCVSS 9.8EG 9.82023-11-27
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.
- CVE-2023-6274CRITICALCVSS 9.8EG 9.82023-11-24
A vulnerability was found in Byzoro Smart S80 up to 20231108. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /sysmanage/updatelib.php of the component PHP File Handler. The manipula…
- CVE-2023-5822CRITICALCVSS 9.8EG 9.82023-11-22
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3…
- CVE-2023-48031CRITICALCVSS 9.8EG 9.82023-11-17
OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an …
- CVE-2023-6102CRITICALCVSS 9.8EG 9.82023-11-13
A vulnerability, which was classified as problematic, was found in Maiwei Safety Production Control Platform 4.1. Affected is an unknown function of the file /Content/Plugins/uploader/FileChoose.html?fileUrl=/Upload/File/Pics/&parent. The …
- CVE-2023-47129CRITICALCVSS 9.8EG 9.82023-11-10
Statmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload field, PHP files crafted to look like images may be uploaded. This only affects forms using …
- CVE-2023-5601CRITICALCVSS 9.8EG 9.82023-11-06
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
- CVE-2023-42802CRITICALCVSS 9.8EG 9.82023-11-02
GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server …
- CVE-2023-5360CRITICALCVSS 9.8EG 9.82023-10-31
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
- CVE-2023-5790CRITICALCVSS 9.8EG 9.82023-10-26
A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads …
- CVE-2023-45554CRITICALCVSS 9.8EG 9.82023-10-25
File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.
- CVE-2020-36706CRITICALCVSS 9.8EG 9.82023-10-20
The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0.…
- CVE-2023-45384CRITICALCVSS 9.8EG 9.82023-10-19
KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php
- CVE-2023-45952CRITICALCVSS 9.8EG 9.82023-10-17
An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2023-4666CRITICALCVSS 9.8EG 9.82023-10-16
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
- CVE-2023-45856CRITICALCVSS 9.8EG 9.82023-10-14
qdPM 9.2 allows remote code execution by using the Add Attachments feature of Edit Project to upload a .php file to the /uploads URI.
- CVE-2023-43696CRITICALCVSS 9.8EG 9.82023-10-09
Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.
- CVE-2023-43269CRITICALCVSS 9.8EG 9.82023-10-05
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.
- CVE-2023-44974CRITICALCVSS 9.8EG 9.82023-10-03
An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2023-44973CRITICALCVSS 9.8EG 9.82023-10-03
An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- CVE-2023-44009CRITICALCVSS 9.8EG 9.82023-10-02
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
- CVE-2023-44008CRITICALCVSS 9.8EG 9.82023-10-02
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
- CVE-2023-5227CRITICALCVSS 9.8EG 9.82023-09-30
Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
- CVE-2023-5277CRITICALCVSS 9.8EG 9.82023-09-29
A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file student_avatar.php. The manipulation of the argument change leads to un…
- CVE-2023-43478CRITICALCVSS 9.8EG 9.82023-09-20
fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware images and configuration backups, which could allow them to alter the firmware or the con…
- CVE-2023-5034CRITICALCVSS 9.8EG 9.82023-09-18
A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. T…
- CVE-2023-4988CRITICALCVSS 9.8EG 9.82023-09-15
A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=system&action=uploadImg. The manipulation of the argument imgFile leads to unrestricted uploa…
- CVE-2023-40784CRITICALCVSS 9.8EG 9.82023-09-12
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →