CWE-434— Unrestricted Upload of File with Dangerous Type
3,917 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-434page 3 of 79
- CVE-2015-6000HIGHCVSS 8.8EG 8.82020-02-06
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote authenticated users to execute arbitrary …
- CVE-2015-7339HIGHCVSS 8.8EG 8.82020-03-09
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
- CVE-2015-7341HIGHCVSS 8.8EG 8.82020-03-09
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
- CVE-2015-9259CRITICALCVSS 9.8EG 9.82018-03-31
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker…
- CVE-2015-9263CRITICALCVSS 9.8EG 9.82018-08-27
An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
- CVE-2015-9271CRITICALCVSS 9.8EG 9.82018-10-04
The VideoWhisper videowhisper-video-conference-integration plugin 4.91.8 for WordPress allows remote attackers to execute arbitrary code because vc/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrat…
- CVE-2015-9338HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
- CVE-2015-9339HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
- CVE-2015-9340HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
- CVE-2015-9341HIGHCVSS 7.5EG 7.52019-08-22
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
- CVE-2015-9402HIGHCVSS 8.8EG 8.82019-09-20
The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload.
- CVE-2015-9471CRITICALCVSS 9.8EG 9.82019-10-10
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
- CVE-2015-9479CRITICALCVSS 9.8EG 9.82019-10-10
The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.
- CVE-2015-9499CRITICALCVSS 9.8EG 9.82019-10-22
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.
- CVE-2016-10036CRITICALCVSS 9.8EG 9.82018-05-01
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write t…
- CVE-2016-10258MEDIUMCVSS 6.8EG 6.82018-04-11
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another admi…
- CVE-2016-10751HIGHCVSS 7.2EG 7.22019-05-24
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?pa…
- CVE-2016-10752CRITICALCVSS 9.8EG 9.82019-05-24
serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code because it mishandles an extensionless filename during a rename, as demonstrated by "php" as a filename.
- CVE-2016-10758HIGHCVSS 8.8EG 8.82019-05-24
PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.
- CVE-2016-10954CRITICALCVSS 9.8EG 9.82019-09-13
The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
- CVE-2016-10955CRITICALCVSS 9.8EG 9.82019-09-13
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
- CVE-2016-10958HIGHCVSS 7.5EG 7.52019-09-16
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.
- CVE-2016-10959MEDIUMCVSS 6.5EG 6.52019-09-16
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.
- CVE-2016-10995CRITICALCVSS 9.8EG 9.82019-09-18
The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
- CVE-2016-11020CRITICALCVSS 9.8EG 9.82020-02-25
Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.
- CVE-2016-15033CRITICALCVSS 9.8EG 9.82023-06-07
The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthen…
- CVE-2016-15042CRITICALCVSS 9.8EG 9.82024-10-16
The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfr…
- CVE-2016-15043CRITICALCVSS 9.8EG 9.82025-07-19
The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to uploa…
- CVE-2016-15046HIGHCVSS 8.6EG 0.02025-07-25
A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ instance (running on port …
- CVE-2016-20052CRITICALCVSS 9.8EG 9.82026-04-04
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the m…
- CVE-2016-6918CRITICALCVSS 9.8EG 9.82020-03-09
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
- CVE-2016-7443CRITICALCVSS 9.8EG 9.82018-03-07
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
- CVE-2016-8515HIGHCVSS 8.8EG 8.82018-02-15
A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all versions prior to 7.6.
- CVE-2016-9492CRITICALCVSS 9.8EG 9.82018-07-13
The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to unrestricted upload of dangerous file types. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous e…
- CVE-2017-11357CRITICALCVSS 9.8EG 9.8⚠ KEV2017-08-23
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVE-2017-11561MEDIUMCVSS 6.5EG 6.52019-05-23
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- CVE-2017-14521HIGHCVSS 8.8EG 8.82018-01-26
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
- CVE-2017-1499HIGHCVSS 8.8EG 8.82018-02-14
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106.
- CVE-2017-15549HIGHCVSS 8.8EG 8.82018-01-05
An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote authenticated malicious user with low privi…
- CVE-2017-16251HIGHCVSS 8.8EG 8.82018-03-13
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an a…
- CVE-2017-16594MEDIUMCVSS 6.5EG 6.52018-01-23
This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing auth…
- CVE-2017-16736HIGHCVSS 7.5EG 7.52018-01-12
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.
- CVE-2017-16772HIGHCVSS 8.8EG 8.82018-03-22
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
- CVE-2017-17976CRITICALCVSS 9.8EG 9.82018-01-26
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
- CVE-2017-18048HIGHCVSS 8.8EG 8.82018-01-23
Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
- CVE-2017-18435HIGHCVSS 7.3EG 7.32019-08-02
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
- CVE-2017-18592HIGHCVSS 7.5EG 7.52019-08-27
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
- CVE-2017-20021MEDIUMCVSS 6.5EG 9.82022-06-09
A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the a…
- CVE-2017-20063MEDIUMCVSS 6.3EG 6.32022-06-20
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been classified as critical. Affected is an unknown function of the file /filemanager/upload/drop of the component File Upload. The manipulation leads to improper privilege managem…
- CVE-2017-2617HIGHCVSS 7.6EG 7.82018-05-22
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.
Map vulnerabilities like CWE-434 to your infrastructure
EchelonGraph correlates every CVE — across CWE-434 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →