Weaknesses of type CWE-434

3,096 results

Upload sem restrição de arquivo com tipo perigoso

Ocorre quando uma aplicação aceita upload de arquivos sem validar adequadamente seu tipo, extensão ou conteúdo. Um atacante pode enviar executáveis, scripts ou outros arquivos maliciosos, que serão armazenados ou executados no servidor, comprometendo sua integridade e segurança.

Example

Um formulário de perfil aceita qualquer arquivo como 'foto do usuário' sem checar extensão ou MIME type. Um atacante envia um arquivo .exe ou .php renomeado como .jpg, que é salvo no diretório web e posteriormente executado quando acessado, permitindo execução de código remoto.

How to mitigate

Valide uploads checando MIME type real (não apenas extensão), restrinja tipos permitidos de forma explícita, armazene arquivos fora da raiz web, desabilite execução de scripts no diretório de upload e considere usar vírus scanner. Implemente whitelist rigorosa, nunca blacklist.

CVE-2025-12846HIGHBlocksy Companion <= 2.1.19 - Authenticated (Author+) Arbitrary File Upload via SVG Upload BypassEPSS 0.7%CVE-2025-5746CRITICALDrag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2025-54944MEDIUMSUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous TypeEPSS 0.7%CVE-2023-47711LOWIBM Security Guardium denial of serviceEPSS 0.7%CVE-2023-26690HIGHFile Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in tEPSS 0.7%CVE-2022-2750MEDIUMSourceCodester Company Website CMS Add Service add-service.php unrestricted uploadEPSS 0.7%CVE-2022-2736MEDIUMSourceCodester Company Website CMS Background Upload Logo Icon updatelogo.php unrestricted uploadEPSS 0.7%CVE-2022-2740MEDIUMSourceCodester Company Website CMS Add Blog add-blog.php unrestricted uploadEPSS 0.7%CVE-2022-2751MEDIUMSourceCodester Company Website CMS add-portfolio.php unrestricted uploadEPSS 0.7%CVE-2024-51364HIGHAn arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.EPSS 0.7%CVE-2025-30131CRITICALAn issue was discovered on IROAD Dashcam FX2 devices. An unauthenticated file upload endpoint can be leveraged to execute arbitrary commandsEPSS 0.7%CVE-2023-52154HIGHFile Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTEPSS 0.7%CVE-2022-2872LOWUnrestricted Upload of File with Dangerous Type in octoprint/octoprintEPSS 0.7%CVE-2024-10994MEDIUMCodezips Online Institute Management System edit_user.php unrestricted uploadEPSS 0.7%CVE-2023-40784CRITICALDedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.EPSS 0.7%CVE-2024-2890CRITICALWordPress Tumult Hype Animations plugin <= 1.9.12 - Arbitrary File Upload vulnerabilityEPSS 0.7%CVE-2019-25296CRITICALWP Cost Estimation <= 9.642 - Missing Authorization to Arbitrary File Upload/DeleteEPSS 0.7%CVE-2026-41587HIGHCI4MS: Unrestricted PHP File Upload via Theme Installation Leads to Authenticated Remote Code ExecutionEPSS 0.7%CVE-2024-56975CRITICALInvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_fileEPSS 0.7%CVE-2025-54071CRITICALRomM's authenticated arbitrary file write vulnerability can lead to Remote Code ExecutionEPSS 0.7%