← Back
CWE-434

4,211 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,211)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dasinfomedia
1Annual Maintenance Contract Management System
May 13, 2026
Sep 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
1Teamworktec
1Ticketplus
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
1Teamworktec
1Photo Fusion
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
1Teamworktec
1Job Links
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
1Manageengine
1Desktop Central
May 13, 2026
Sep 28, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
1Claydip
1Airbnb Clone
May 13, 2026
Sep 26, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file w...Show more
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.Show less
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Tecnovision
1Dlx Spot Player4
May 13, 2026
Sep 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
1Netsweeper
1Netsweeper
May 13, 2026
Sep 19, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on th...Show more
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.Show less
3Apache
NetappRedhat
227 Mode Transition Tool
Enterprise Linux DesktopEnterprise Linux Eus+19 more
Apr 21, 2026
Sep 19, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci...Show more
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.Show less
1Flickr Picture Backup Project
1Flickr Picture Backup
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.
1Membership Simplified Project
1Membership Simplified
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and ha...Show more
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.Show less
1Wp2android Turn Wp Site Into Android App Project
1Wp2android Turn Wp Site Into Android App
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
1Webapp Builder Project
1Webapp Builder
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
1Mobile App Builder By Wappress Project
1Mobile App Builder By Wappress
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
1Mobile Friendly App Builder By Easytouch Project
1Mobile Friendly App Builder By Easytouch
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allo...Show more
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.Show less
1Blackcat Cms
1Blackcat Cms
May 13, 2026
Sep 12, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
1Blog Project
1Blog
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
1Imagely
1Nextgen Gallery
May 13, 2026
Sep 12, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
1Typo3
1Typo3
May 13, 2026
Sep 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a...Show more
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.Show less