← Back
CWE-434

4,377 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,377)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sofawiki Project
1Sofawiki
Jun 17, 2026
May 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.
1Mw Wp Form Project
1Mw Wp Form
Jun 17, 2026
May 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
1Microengine
1Mailform
Jun 17, 2026
May 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary fil...Show more
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.Show less
1Wcms
1Wcms
Jun 17, 2026
May 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custo...Show more
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code to execute scripts to trigger command execution.Show less
1Rental Module Project
1Rental Module
Jun 17, 2026
May 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web S...Show more
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15.Show less
1Perfree
1Perfreeblog
Jun 17, 2026
May 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
1Simple Photo Gallery Project
1Simple Photo Gallery
Jun 17, 2026
May 17, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated r...Show more
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-229282 is the identifier assigned to this vulnerability.Show less
1Freeguppy
1Guppy
Jun 17, 2026
May 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.
1Oretnom23
1Online Computer And Laptop Store
Jun 17, 2026
May 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.
1Tongda2000
1Tongda Office Anywhere
Jun 17, 2026
May 16, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unrestricted upload. It is possible to initia...Show more
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-229149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1S9y
1Serendipity
Jun 17, 2026
May 16, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
1Storage Unit Rental Management System Project
1Storage Unit Rental Management System
Jun 17, 2026
May 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.
1Extplorer
1Extplorer
Jun 17, 2026
May 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
1Phpok
1Phpok
Jun 17, 2026
May 11, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
1Weaver
1E Office
Jun 17, 2026
May 11, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unres...Show more
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Genesys
1Tftp Server
Jun 17, 2026
May 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.
1Ivanti
1Avalanche
Jun 17, 2026
May 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution.
1Agilepoint
1Agilepoint Nx
Jun 17, 2026
May 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
May 8, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
1Mblog Project
1Mblog
Jun 17, 2026
May 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.