CWE-434

Medium likelihood

Unrestricted Upload of File with Dangerous Type

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

4,013 vulnerabilities with CWE-434
CVE-2025-28915 CRITICAL
ThemeEgg ToolKit <1.2.9 - RCE
CVSS 9.1
CVE-2025-22213 HIGH
Media Manager - Info Disclosure
CVE-2025-2115 MEDIUM
Zzskzy Warehouse Refinement Management System - Improper Access Control
CVSS 6.3
CVE-2025-25361 CRITICAL
Publiccms - Unrestricted File Upload
CVSS 9.8
CVE-2025-2035 MEDIUM
S-a-zhd Ecommerce-website-using-php - Improper Access Control
CVSS 6.3
CVE-2025-2031 MEDIUM
1000mz Chestnutcms - Improper Access Control
CVSS 6.3
CVE-2025-27411 MEDIUM
REDAXO <5.18.3 - File Upload
CVSS 5.4
CVE-2025-27683 HIGH
Printerlogic Vasion Print < 20.0.1330 - Unrestricted File Upload
CVSS 8.8
CVE-2025-26319 CRITICAL
FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload
CVSS 9.8
CVE-2025-1890 MEDIUM
shishuocms 1.1 - Unrestricted Upload
CVSS 6.3
CVE-2025-1835 MEDIUM
osuuu LightPicture 1.2.2 - Unrestricted Upload
CVSS 6.3
CVE-2025-1834 MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1818 MEDIUM
zj1983 zz <2024-8 - Unrestricted Upload
CVSS 6.3
CVE-2025-1791 MEDIUM
Zorlan SkyCaiji 2.9 - Unrestricted Upload
CVSS 6.3
CVE-2025-26325 CRITICAL
Shopxo - Unrestricted File Upload
CVSS 9.8
CVE-2025-25790 CRITICAL
Foxcms - Unrestricted File Upload
CVSS 9.8
CVE-2025-25784 CRITICAL
Jizhicms - Unrestricted File Upload
CVSS 9.8
CVE-2025-25783 CRITICAL
Emlog - Unrestricted File Upload
CVSS 9.8
CVE-2025-0731 MEDIUM
PV System <unknown - XSS
CVSS 6.5
CVE-2025-1128 CRITICAL
Wpeverest Everest Forms < 3.0.9.5 - Unrestricted File Upload
CVSS 9.8
CVE-2025-1646 HIGH
Lumsoft ERP 8 - Unrestricted Upload
CVSS 7.3
CVE-2025-1598 MEDIUM
Mayurik Best Church Management Software - Improper Access Control
CVSS 6.3
CVE-2025-1593 MEDIUM
Mayurik Best Employee Management System - Improper Access Control
CVSS 4.7
CVE-2025-1590 MEDIUM
Janobe E-learning System - Improper Access Control
CVSS 4.7
CVE-2025-26776 CRITICAL
Chaty Pro <3.3.3 - RCE
CVSS 10.0
Details
Vulnerabilities 4,013
Exploit Likelihood Medium