CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,012 vulnerabilities with CWE-434
CVE-2025-3807 MEDIUM
Zhenfeng13 My-bbs - Improper Access Control
CVSS 6.3
CVE-2025-3798 MEDIUM
WCMS 11 - Unrestricted Upload
CVSS 4.7
CVE-2025-1093 CRITICAL
AIHub theme <1.3.7 - RCE
CVSS 9.8
CVE-2025-3783 MEDIUM
SourceCodester Web-based Pharmacy Product Management System 1.0 - U...
CVSS 6.3
CVE-2025-3765 MEDIUM
Senior-walter Web-based Pharmacy Product Management System - Improper Access Control
CVSS 6.3
CVE-2025-3764 MEDIUM
Senior-walter Web-based Pharmacy Product Management System - Improper Access Control
CVSS 6.3
CVE-2025-39436 CRITICAL
aidraw I Draw <1.0 - RCE
CVSS 9.1
CVE-2025-32682 CRITICAL
RomanCode MapSVG Lite <8.5.34 - RCE
CVSS 9.9
CVE-2025-32660 CRITICAL
Joomsky JS Job Manager < 2.0.2 - Unrestricted File Upload
CVSS 10.0
CVE-2025-32652 CRITICAL
solacewp Solace Extra - Unrestricted Upload
CVSS 9.9
CVE-2025-27282 CRITICAL
rockgod100 Theme File Duplicator <1.3 - UAFDT
CVSS 9.9
CVE-2025-31339 MEDIUM
Wisdom Master Pro <5.3 - File Upload
CVE-2025-39557 CRITICAL
Kadence WP Kadence WooCommerce Email Designer <1.5.14 - RCE
CVSS 9.1
CVE-2025-39538 MEDIUM
WP-Advanced-Search <3.3.9.3 - Code Injection
CVSS 6.6
CVE-2025-1980 HIGH
Ready_ < unknown - RCE
CVE-2025-26927 CRITICAL
EPC AI Hub <1.3.3 - RCE
CVSS 10.0
CVE-2025-3593 MEDIUM
Zhenfeng13 My-blog-layui - Improper Access Control
CVSS 6.3
CVE-2025-3585 MEDIUM
Westboy Cicadascms - Improper Access Control
CVSS 6.3
CVE-2025-3566 HIGH
veal98 XiaoNiuRou Echo 4.2 - Unrestricted Upload
CVSS 7.3
CVE-2025-3565 MEDIUM
Huanfenz Studentmanager - Improper Access Control
CVSS 4.7
CVE-2025-3558 MEDIUM
Ghostxbh Uzy-ssm-mall - Improper Access Control
CVSS 6.3
CVE-2025-32579 CRITICAL
SoftClever Limited Sync Posts <1.0 - RCE
CVSS 9.9
CVE-2025-29017 HIGH
Codeastro Internet Banking System - Unrestricted File Upload
CVSS 8.8
CVE-2025-32215 MEDIUM
Ability, Inc Accessibility Suite <4.18 - XSS
CVSS 6.5
CVE-2025-32206 CRITICAL
LABCAT Processing Projects <1.0.2 - RCE
CVSS 9.1
Details
Vulnerabilities 4,012
Exploit Likelihood Medium