CWE-616
9 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-616page 1 of 1
- CVE-2023-38947HIGHCVSS 7.2EG 7.22023-08-03
An arbitrary file upload vulnerability in the /languages/install.php component of WBCE CMS v1.6.1 allows attackers to execute arbitrary code via a crafted PHP file.
- CVE-2024-28520MEDIUMCVSS 6.5EG 6.52024-04-04
File Upload vulnerability in Byzoro Networks Smart multi-service security gateway intelligent management platform version S210, allows an attacker to obtain sensitive information via the uploadfile.php component.
- CVE-2024-29858CRITICALCVSS 9.8EG 9.82024-03-21
In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.
- CVE-2024-31601CRITICALCVSS 9.8EG 9.82024-04-26
An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component.
- CVE-2024-52305MEDIUMCVSS 6.5EG 6.52024-11-13
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. …
- CVE-2025-52130MEDIUMCVSS 5.4EG 5.42025-08-25
File upload vulnerability in WebErpMesv2 1.17 in the app/Http/Controllers/FactoryController.php controller. This flaw allows an authenticated attacker to upload arbitrary files, including PHP scripts, which can be accessed via direct GET r…
- CVE-2025-59402MEDIUMCVSS 5.4EG 5.42025-09-25
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and…
- CVE-2025-67084CRITICALCVSS 9.9EG 6.52026-01-15
File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).
- CVE-2026-22789MEDIUMCVSS 5.4EG 5.42026-01-12
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload a…
Map vulnerabilities like CWE-616 to your infrastructure
EchelonGraph correlates every CVE — across CWE-616 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →