Weaknesses of type CWE-434

3,112 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-52078MEDIUMFile upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated priviEPSS 0.3%CVE-2026-2146MEDIUMguchengwuyue yshopmall co.yixiang.utils.FileUtil updateAvatar unrestricted uploadEPSS 0.3%CVE-2025-4333MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java uploadFile unrestricted uploadEPSS 0.3%CVE-2025-4305MEDIUMkefaming mayi File.php upload unrestricted uploadEPSS 0.3%CVE-2025-4768MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm PictureServiceImpl.java uploadPicture unrestricted uploadEPSS 0.3%CVE-2026-96515HIGHCommand Injection Vulnerability in Netlink ICT HG323RW RouterEPSS 0.3%CVE-2026-39527MEDIUMWordPress WpStream plugin < 4.11.2 - Arbitrary File Upload vulnerabilityEPSS 0.3%CVE-2025-2702MEDIUMSoftwin WMX3 ImageAdd.ashx ImageAdd unrestricted uploadEPSS 0.3%CVE-2025-2706MEDIUMDigiwin ERP UploadAjaxAPI.ashx unrestricted uploadEPSS 0.3%CVE-2026-42879MEDIUMFacturaScripts: Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product ImagesEPSS 0.3%CVE-2023-5524HIGHM-Files Web Companion allows Remote Code Execution for some filetypesEPSS 0.3%CVE-2025-2671MEDIUMYue Lao Blind Box 月老盲盒 Upload.php base64image unrestricted uploadEPSS 0.3%CVE-2025-14522MEDIUMbaowzh hfly upload_json.php unrestricted uploadEPSS 0.3%CVE-2026-27605MEDIUMChartbrew: Stored Cross-Site Scripting (XSS) via File Upload APIEPSS 0.3%CVE-2025-43750MEDIUMLiferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.EPSS 0.3%CVE-2025-10544HIGHUnrestricted uploading of dangerous file types to AvePoint productsEPSS 0.3%CVE-2025-65806MEDIUMThe E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a nested ZIP (a ZIP coEPSS 0.3%CVE-2024-50620HIGHUnrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CEPSS 0.3%CVE-2025-62065CRITICALWordPress RTMKit plugin <= 1.6.5 - Arbitrary File Upload vulnerabilityEPSS 0.3%CVE-2025-12291MEDIUMashymuzuro Full-Ecommece-Website/Muzuro Ecommerce System Add Product index.php unrestricted uploadEPSS 0.3%