← Back
CWE-434

4,107 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,107)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Simple Exam Reviewer Management System Project
1Simple Exam Reviewer Management System
Jun 17, 2026
Oct 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.
1Eve Ng
1Eve Ng
Jun 17, 2026
Oct 20, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allows attackers to execute arbitrary code via a crafted UNL file.
1Sra Admin Project
1Sra Admin
Jun 17, 2026
Oct 19, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an at...Show more
sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code in "Personal Center" - "Profile Picture Upload" allowing theft of the user's personal information. This issue has been patched in 1.1.2. There are no known workarounds.Show less
1Online Tours & Travels Management System Project
1Online Tours & Travels Management System
Jun 17, 2026
Oct 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code...Show more
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Billing System Project
1Billing System
Jun 17, 2026
Oct 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
1Zigor
1Zgr Tps200 Ng Firmware
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modific...Show more
In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.Show less
1Boxbilling
1Boxbilling
Jun 17, 2026
Oct 17, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
1Gin Vue Admin Project
1Gin Vue Admin
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin u...Show more
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.Show less
1Chamilo
1Chamilo
Jun 17, 2026
Oct 17, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web direc...Show more
Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory.Show less
174cms
174cmsse
Jun 17, 2026
Oct 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.
1Oretnom23
1Simple Cold Storage Management System
Jun 17, 2026
Oct 17, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the co...Show more
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.Show less
1Gin Vue Admin Project
1Gin Vue Admin
Jun 17, 2026
Oct 14, 2022
N/A· v4
9.0 CRITICAL· v3
N/A· v2
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin...Show more
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin’s cookie leading to account takeover.Show less
1Wedding Planner Project
1Wedding Planner
Jun 17, 2026
Oct 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
1Wedding Planner Project
1Wedding Planner
Jun 17, 2026
Oct 14, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a cra...Show more
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Oct 13, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code v...Show more
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Oct 13, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary c...Show more
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
1Oretnom23
1Human Resource Management System
Jun 17, 2026
Oct 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component...Show more
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.Show less
1Church Management System Project
1Church Management System
Jun 17, 2026
Oct 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
1Dedecms
1Dedecms
Jun 17, 2026
Oct 12, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
1Interspire
1Email Marketer
Jun 17, 2026
Oct 11, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NO...Show more
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NOTE: this issue exists because of an incomplete fix for CVE-2018-19550.Show less