← Back
CWE-434

4,380 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,380)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Saho
2Adm 100 Firmware
Adm 100fp Firmware
Jun 17, 2026
Aug 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute...Show more
Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or disrupt service. Show less
1Laiketui
1Laiketui
Jun 17, 2026
Aug 27, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST R...Show more
A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&action=user&m=upload of the component POST Request Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-238160.Show less
1Edetw
1U Office Force
Jun 17, 2026
Aug 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary...Show more
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service. Show less
1Pandorafms
1Pandora Fms
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands...Show more
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.Show less
1Boidcms
1Boidcms
Jul 9, 2026
Aug 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
1Happysoft
1Nbs&happysoftwechat
Jun 17, 2026
Aug 18, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launc...Show more
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237512.Show less
1Acyba
1Acymailing Starter
Jun 17, 2026
Aug 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
1Online Travel Agency System Project
1Online Travel Agency System
Jun 17, 2026
Aug 17, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.
1Online Travel Agency System Project
1Online Travel Agency System
Jun 17, 2026
Aug 17, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.
1Campcodes
1Complete Online Matrimonial Website System Script
Jun 17, 2026
Aug 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
1Wolf18
1Easyadmin8
Jun 17, 2026
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.
1Tigergraph
1Tigergraph
Jun 17, 2026
Aug 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of...Show more
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).Show less
1Tigergraph
1Tigergraph
Jun 17, 2026
Aug 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload cu...Show more
An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into the platform. An attacker who has filesystem access on a remote TigerGraph system can alter the behavior of the database against the will of the database administrator; thus effectively bypassing the built in RBAC controls.Show less
1Bloofox
1Bloofoxcms
Jun 17, 2026
Aug 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.
1Ivanti
1Avalanche
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
1Ivanti
1Avalanche
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.
1Phpjabbers
1Ticket Support Script
Jun 17, 2026
Aug 10, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
1Full
1Full Customer
Jun 17, 2026
Aug 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attacker...Show more
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.Show less
1Pharmacy Management System Project
1Pharmacy Management System
Jun 17, 2026
Aug 6, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation le...Show more
A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-236221 was assigned to this vulnerability.Show less
1Sem Cms
1Semcms
Jun 17, 2026
Aug 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.