← Back
CWE-434

4,365 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

JSON object

Loading...

CVEs (4,365)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Tecnovision
1Dlx Spot Player4
May 13, 2026
Sep 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.
1Netsweeper
1Netsweeper
May 13, 2026
Sep 19, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on th...Show more
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.Show less
3Apache
NetappRedhat
227 Mode Transition Tool
Enterprise Linux DesktopEnterprise Linux Eus+19 more
Aug 6, 2026
Sep 19, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci...Show more
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.Show less
1Flickr Picture Backup Project
1Flickr Picture Backup
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.
1Membership Simplified Project
1Membership Simplified
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and ha...Show more
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.Show less
1Wp2android Turn Wp Site Into Android App Project
1Wp2android Turn Wp Site Into Android App
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
1Webapp Builder Project
1Webapp Builder
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
1Mobile App Builder By Wappress Project
1Mobile App Builder By Wappress
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
1Mobile Friendly App Builder By Easytouch Project
1Mobile Friendly App Builder By Easytouch
May 13, 2026
Sep 14, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allo...Show more
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.Show less
1Blackcat Cms
1Blackcat Cms
May 13, 2026
Sep 12, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
1Blog Project
1Blog
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
1Imagely
1Nextgen Gallery
May 13, 2026
Sep 12, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
1Typo3
1Typo3
May 13, 2026
Sep 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a...Show more
Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.Show less
1Zohocorp
1Manageengine Firewall Analyzer
May 13, 2026
Sep 4, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can c...Show more
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.Show less
1Blackcat Cms
1Blackcat Cms
May 13, 2026
Aug 31, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.
1Kamailio
1Kamailio
May 13, 2026
Aug 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
1Ibm
1Sametime
May 13, 2026
Aug 29, 2017
N/A· v4
5.5 MEDIUM· v3
6.0 MEDIUM· v2
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with us...Show more
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.Show less
110web
1Photo Gallery
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
2Automatedlogic
Carrier
3Automatedlogic Webctrl
I VuSitescan Web
May 13, 2026
Aug 25, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 a...Show more
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.Show less