Weaknesses of type CWE-434

3,080 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-48148CRITICALWordPress StoreKeeper for WooCommerce Plugin <= 14.4.4 - Arbitrary File Upload VulnerabilityEPSS 16.7%CVE-2021-20022HIGHSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to EPSS 16.5%KEVCVE-2024-44871HIGHAn arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via upEPSS 16.2%CVE-2025-3914HIGHAeropage Sync for Airtable <= 3.2.0 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 16.2%CVE-2021-39141HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 16.1%CVE-2024-24399HIGHAn arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code EPSS 15.6%CVE-2022-1103—Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File UploadEPSS 15.6%CVE-2022-1565HIGHImport any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File UploadEPSS 15.4%CVE-2022-45275HIGHAn arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing System v1.0 allows attEPSS 15.3%CVE-2018-17936—NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files toEPSS 15.3%CVE-2023-41998CRITICALArcserve UDP Unauthenticated RCEEPSS 15.3%CVE-2021-21350MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 15.2%CVE-2025-34040CRITICALSeeyon Zhiyuan OA System Path Traversal File UploadEPSS 15.1%CVE-2026-48908CRITICALJoomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2EPSS 15.1%CVE-2025-34077CRITICALWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCEEPSS 15.1%CVE-2023-5154MEDIUMD-Link DAR-8000 changelogo.php unrestricted uploadEPSS 15.1%CVE-2024-10392CRITICALAI Power: Complete AI Pack <= 1.8.89 - Unauthenticated Arbitrary File UploadEPSS 15.0%CVE-2026-56291CRITICALJoomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1EPSS 14.9%KEVCVE-2026-30821HIGHFlowise: Arbitrary File Upload via MIME SpoofingEPSS 14.7%CVE-2023-4596CRITICALForminator <= 1.24.6 - Unauthenticated Arbitrary File UploadEPSS 14.3%